Android应用接入Duende IdentityServer登录失败问题求助
问题根源及解决方法
核心问题分析
你的问题本质是授权流程入口错误,加上客户端与Android端的端点配置不匹配,导致登录页面无法获取授权上下文(即returnUrl),最终无法完成回调。
具体错误点与修复步骤
1. 修正Duende IdentityServer客户端配置(appsettings.json)
当前AndroidID客户端存在两处关键配置错误,需调整:
"Clients": { "AppName": { "Profile": "IdentityServerSPA", }, "AndroidID": { "Profile": "IdentityServerSPA", "Enabled": true, "ClientId": "AndroidID", "RequireClientSecret": false, "ClientName": "AndroidApp", "ClientSecrets": [ { "Value": "" } ], "RequirePkce": true, "AllowedGrantTypes": [ "code" ], // 移除不需要的client_credentials、implicit,仅保留授权码流程 "AllowedScopes": [ "openid", "profile", "email", "phone", "SIGADAPI" ], // 与Android端scope保持一致,替换原错误的"api" "RedirectUris": [ "https://aaa/authentication/login-callback" ], // 替换为Android端实际使用的回调地址 "RequireConsent": false, "AllowOfflineAccess": true, "PostLogoutRedirectUris": [ "https://aaa/connect/endsession" ] // 补充登出回调地址 } }
2. 修正Android端AppAuth配置
多个端点配置不符合IdentityServer标准,需调整:
{ "client_id": "AndroidID", "redirect_uri": "https://aaa/authentication/login-callback", "end_session_redirect_uri": "https://aaa/connect/endsession", "authorization_scope": "openid email profile SIGADAPI", "authorization_endpoint_uri": "https://aaa/connect/authorize", // 替换为IdentityServer授权端点,而非直接登录页面 "token_endpoint_uri": "https://aaa/connect/token", "registration_endpoint_uri": "", "user_info_endpoint_uri": "https://aaa/connect/userinfo", // 替换为标准用户信息端点 "https_required": true, "end_session_endpoint": "https://aaa/connect/endsession", "client_secret" : "", "response_types": "code", "jwks_uri": "https://aaa/.well-known/openid-configuration/jwks", "revocation_endpoint": "https://aaa/connect/revocation", "grant_types": [ "code" ], // 仅保留授权码流程 "scopes_supported" : [ "openid", "profile", "email", "phone", "SIGADAPI" ] }
3. 确保登录页面正确处理授权上下文
登录页面(Login.cshtml)的returnUrl需由IdentityServer的/connect/authorize端点跳转携带,而非直接访问登录页面。确认:
- 客户端发起授权请求时,目标是
/connect/authorize而非直接登录页面,此时returnUrl会自动包含授权上下文 - 登录逻辑中,调用
_signInManager.PasswordSignInAsync成功后,必须执行return Redirect(returnUrl)跳转,不能忽略该参数
验证流程
- 重启IdentityServer服务,确保配置生效
- Android端发起授权请求,此时会先进入
/connect/authorize端点,再引导至登录页面,returnUrl将正常携带授权上下文 - 登录成功后,系统会自动回调至Android端配置的
redirect_uri,完成令牌获取流程
内容的提问来源于stack exchange,提问作者Andrei Dobrin
相关产品推荐
相关产品推荐

