Duende IdentityServer报错:Scope openid未找到或不被资源指示器支持
Duende IdentityServer 范围匹配报错问题
问题描述
按照官方示例发送授权请求:
GET /connect/authorize?
client_id=tyr-idp&
scope=openid&
response_type=code&
redirect_uri=https://localhost_4200/login&
state=check123
日志抛出错误:
Scope openid not found in store or not supported by requested resource indicators.
无论创建哪种身份资源并在请求scope中指定,都会出现类似的“未找到或不被支持”错误。
已配置/排查操作
客户端配置
- 授权类型设置为
authorization_code,配置了重定向URI,关闭客户端密钥要求 - 将
oidc范围添加到客户端允许的范围列表中 - 通过EF查询确认客户端已包含预期范围:
Client client = context.Clients .Include(a=>a.AllowedGrantTypes) .Include(a=>a.AllowedScopes) .Include(a=>a.RedirectUris) .First(a => a.ClientId == "tyr-idp"); - 尝试手动创建新客户端并保存,问题依旧:
Client client = new(){ ClientId = "client_id", ClientName = "client_name", RequireClientSecret = false, RequirePkce = false, AllowOfflineAccess = true, AllowedGrantTypes = new(){ new(){ GrantType = "authorization_code" }}, AllowedScopes = new(){ new() { Scope = "openid" } , new() { Scope = "oidc" } }, RedirectUris = new(){ new(){ RedirectUri = "https://localhost:4200/login" }} }; context.Clients.Add(client); context.SaveChanges();
- 授权类型设置为
身份资源配置
- 按照官方文档创建了名为
oidc的身份资源 - 执行SQL查询
select * from IdentityResources,返回一行数据:Scope值为oidc,ClientId值为13(对应客户端ID) - 为该资源添加了默认的
sub声明及自定义声明
- 按照官方文档创建了名为
补充信息
- 另一个测试请求:
GET /connect/authorize?client_id=tyr-idp&scope=tyr-trifecta&response_type=code&redirect_uri=https://localhost:7101/spa
- 客户端范围截图:

- API资源截图:

- 身份资源截图:

内容的提问来源于stack exchange,提问作者Konrad Viltersten
相关产品推荐
相关产品推荐

