.NET 7从IdentityServer v6迁移OpenIddict:客户端令牌配置问题
IdentityServer v6 到 OpenIddict 客户端令牌配置映射
以下是你原IdentityServer Client类中的令牌相关配置,在OpenIddict OpenIddictApplicationDescriptor中的对应实现及完整代码:
配置项对应关系
- AllowedGrantTypes = GrantTypes.ResourceOwnerPassword:在
Permissions集合中添加Permissions.GrantTypes.ResourceOwnerPassword,移除原AuthorizationCode相关权限(ResourceOwnerPassword授权无需这些)。 - AllowOfflineAccess = true:添加
Permissions.GrantTypes.RefreshToken,允许客户端使用刷新令牌续期访问令牌。 - AccessTokenLifetime:直接设置
AccessTokenLifetime属性为对应TimeSpan值。 - RefreshTokenUsage = TokenUsage.ReUse:设置
RefreshTokenReuseEnabled = true,允许刷新令牌重复使用。 - AbsoluteRefreshTokenLifetime = 0:设置
RefreshTokenAbsoluteLifetime = TimeSpan.Zero,表示刷新令牌无绝对过期时间。 - RefreshTokenExpiration = TokenExpiration.Sliding:设置
RefreshTokenSlidingLifetime为对应TimeSpan值,OpenIddict会自动启用滑动过期策略,每次刷新令牌时延长其有效期。 - AllowedScopes = ["scope_1", "scope_2"]:保持
Permissions中前缀为Permissions.Prefixes.Scope的权限项,与原scope名称一致。
完整客户端初始化代码
await manager.CreateAsync(new OpenIddictApplicationDescriptor { ClientId = "client_example", ClientSecret = clientSecret, // ResourceOwnerPassword授权无需用户显式同意,设置为Implicit ConsentType = ConsentTypes.Implicit, DisplayName = "Client Example Test", Permissions = { Permissions.Endpoints.Token, // ResourceOwnerPassword仅需Token端点权限 Permissions.GrantTypes.ResourceOwnerPassword, Permissions.GrantTypes.RefreshToken, // 对应AllowOfflineAccess=true $"{Permissions.Prefixes.Scope}scope_1", $"{Permissions.Prefixes.Scope}scope_2" }, // 令牌生命周期配置 AccessTokenLifetime = TimeSpan.FromSeconds(accessTokenLifetime), RefreshTokenReuseEnabled = true, RefreshTokenAbsoluteLifetime = TimeSpan.Zero, RefreshTokenSlidingLifetime = TimeSpan.FromSeconds(refreshTokenLifetime) })
注:如果你的客户端需要支持多种授权类型,可以保留对应的端点和权限配置;若仅使用ResourceOwnerPassword,上述配置已完全匹配原IdentityServer的行为。
内容的提问来源于stack exchange,提问作者Vũ Anh Nguyễn
相关产品推荐
相关产品推荐

