Next-Auth自定义OIDC PKCE认证报错:client_secret_basic需client_secret
问题:NextAuth自定义OIDC PKCE流触发client_secret认证错误
环境:Next.js 13.4.19、Node.js 18.12.1
在next-auth-example项目中,因重复路由删除了app/api/auth/[...nextauth],配置自定义OIDC PKCE流的OAuth Provider后,认证流程收尾阶段触发[next-auth][error][OAUTH_CALLBACK_ERROR],提示“client_secret_basic client authentication method requires a client_secret”,但该PKCE凭证本身无client_secret。
配置代码:
{ id:"Umar", name: "umarPKCTNextAuth", type: "oauth", wellKnown:"https://auth.folderit.com/.well-known/openid-configuration", checks: ["pkce","state"], idToken: true, clientId: process.env.AUTH0_ID, authorization: { params: { scope: "openid" } }, profile(profile: { id: any; kakao_account: { profile: { nickname: any; profile_image_url: any }; email: any } }) { return { id: profile.id, name: profile.kakao_account?.profile.nickname, email: profile.kakao_account?.email, image: profile.kakao_account?.profile.profile_image_url, } } },
解决方案
- 显式指定客户端认证方法为
none
PKCE流程不需要client_secret,需在Provider配置中添加clientAuthMethod: "none",告知NextAuth不要使用默认的client_secret_basic认证方式:
{ id:"Umar", name: "umarPKCTNextAuth", type: "oauth", wellKnown:"https://auth.folderit.com/.well-known/openid-configuration", checks: ["pkce","state"], idToken: true, clientId: process.env.AUTH0_ID, clientAuthMethod: "none", // 新增该行配置 authorization: { params: { scope: "openid" } }, profile(profile: { id: any; kakao_account: { profile: { nickname: any; profile_image_url: any }; email: any } }) { return { id: profile.id, name: profile.kakao_account?.profile.nickname, email: profile.kakao_account?.email, image: profile.kakao_account?.profile.profile_image_url, } } },
确认OIDC提供商的PKCE支持配置
访问https://auth.folderit.com/.well-known/openid-configuration,查看token_endpoint_auth_methods_supported是否包含none。如果不包含,需在提供商后台将该客户端的认证方式设置为PKCE(无client_secret)。恢复必要的路由文件
删除app/api/auth/[...nextauth]可能导致NextAuth回调路由失效,建议恢复该文件以保证路由正常:
// app/api/auth/[...nextauth]/route.ts import NextAuth from "next-auth"; import { authOptions } from "@/lib/auth"; // 替换为你的auth配置文件路径 const handler = NextAuth(authOptions); export { handler as GET, handler as POST };
内容的提问来源于stack exchange,提问作者Muhammad Umar Khan
相关产品推荐
相关产品推荐

