You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Duende IdentityServer报错:Scope openid未找到或不被资源指示器支持

Duende IdentityServer 范围匹配报错问题

问题描述

按照官方示例发送授权请求:

GET /connect/authorize?
client_id=tyr-idp&
scope=openid&
response_type=code&
redirect_uri=https://localhost_4200/login&
state=check123

日志抛出错误:

Scope openid not found in store or not supported by requested resource indicators.

无论创建哪种身份资源并在请求scope中指定,都会出现类似的“未找到或不被支持”错误。

已配置/排查操作

  1. 客户端配置

    • 授权类型设置为authorization_code,配置了重定向URI,关闭客户端密钥要求
    • 将oidc范围添加到客户端允许的范围列表中
    • 通过EF查询确认客户端已包含预期范围:
      Client client = context.Clients
        .Include(a=>a.AllowedGrantTypes)
        .Include(a=>a.AllowedScopes)
        .Include(a=>a.RedirectUris)
        .First(a => a.ClientId == "tyr-idp");
      
    • 尝试手动创建新客户端并保存,问题依旧:
      Client client = new(){
        ClientId = "client_id",
        ClientName = "client_name",
        RequireClientSecret = false,
        RequirePkce = false,
        AllowOfflineAccess = true,
        AllowedGrantTypes = new(){ new(){ GrantType = "authorization_code" }},
        AllowedScopes = new(){ new() { Scope = "openid" } , new() { Scope = "oidc" } },
        RedirectUris = new(){ new(){ RedirectUri = "https://localhost:4200/login" }}
      };
      context.Clients.Add(client);
      context.SaveChanges();
      
  2. 身份资源配置

    • 按照官方文档创建了名为oidc的身份资源
    • 执行SQL查询select * from IdentityResources,返回一行数据:Scope值为oidc,ClientId值为13(对应客户端ID)
    • 为该资源添加了默认的sub声明及自定义声明

补充信息

  • 另一个测试请求:

    GET /connect/authorize?client_id=tyr-idp&scope=tyr-trifecta&response_type=code&redirect_uri=https://localhost:7101/spa

  • 客户端范围截图:
    客户端范围截图
  • API资源截图:
    API资源截图
  • 身份资源截图:
    身份资源截图

内容的提问来源于stack exchange,提问作者Konrad Viltersten

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 03:24:55