Duende Identity Server 4登录后无法重定向至React客户端问题排查
Duende Identity Server登录后未重定向回React客户端问题解决
问题场景
基于Code授权类型,使用Duende Identity Server实现认证功能,React客户端集成react-oidc-context作为OpenID Connect客户端。Identity Server(IS)已配置启动时添加测试用户的逻辑与基础UI,但登录后出现异常:在IS登录页输入测试用户凭证并点击登录后,页面仅刷新,顶部显示已登录用户名,但未自动重定向回React客户端。
排查尝试
- 将所有端点切换为HTTPS
- 在IS的Program.cs中配置Cookie策略(配置代码见下文)
问题根源与解决方法
问题源于登录页模型(Pages/Account/Login/Index.cshtml.cs)的默认实现,向页面模型注入SignInManager替代默认的TestUserStore后,重定向功能恢复正常。
相关配置信息
Identity Server客户端配置
new Client { ClientId = "spa", ClientName = "React Single Page Application", ClientSecrets = { new Secret("secret") }, RequireClientSecret = false, ClientUri = "https://localhost:44430", RedirectUris = { "https://localhost:44430/fetch-data" }, PostLogoutRedirectUris = { "https://localhost:44430" }, AllowedGrantTypes = GrantTypes.Code, RequirePkce = false, AllowAccessTokensViaBrowser = true, AllowedScopes = { IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, "weather", }, },
React客户端配置
{ authority: "https://localhost:7123", client_id: "spa", client_secret: "secret", redirect_uri: "https://localhost:44430/fetch-data", post_logout_redirect_uri: 'https://localhost:44430', response_type: 'code', scope: 'weather', userStore: new WebStorageStateStore({ store: window.localStorage }), };
Identity Server服务配置(Program.cs)
builder.Services.AddIdentity<AppUser, IdentityRole>() .AddEntityFrameworkStores<AppIdentityDbContext>() .AddDefaultTokenProviders(); builder.Services.AddIdentityServer(options => { options.IssuerUri = "https://localhost:7123"; options.Events.RaiseErrorEvents = true; options.Events.RaiseInformationEvents = true; options.Events.RaiseFailureEvents = true; options.Events.RaiseSuccessEvents = true; options.EmitStaticAudienceClaim = true; }) .AddInMemoryIdentityResources(Config.GetIdentityResources()) .AddInMemoryApiScopes(Config.GetApiScopes()) .AddInMemoryApiResources(Config.GetApisResources()) .AddInMemoryClients(Config.GetClients(builder.Configuration)) .AddTestUsers(TestUsers.Users) .AddAspNetIdentity<AppUser>();
尝试过的Cookie策略配置
app.UseCookiePolicy(new CookiePolicyOptions { HttpOnly = HttpOnlyPolicy.None, MinimumSameSitePolicy = SameSiteMode.None, Secure = CookieSecurePolicy.Always });
内容的提问来源于stack exchange,提问作者Johny
相关产品推荐
相关产品推荐

