You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

JWT令牌过大触发防火墙IPS拦截问题求助(附配置)

JWT令牌过大被IPS防火墙截断导致前端ERRCONRESET问题求助

我们采用Angular前端+IdentityServer4认证服务架构,认证完成后前端会调用用户信息接口,该接口通过HTTP请求头中的Bearer令牌返回用户声明。但在启用IPS(入侵防御系统,如Stormshield、Palo alto、Azure)的部分防火墙环境下,因JWT令牌内容超过1000字节被截断重编码,导致前端出现ERRCONRESET错误。

流程总结

  • Angular前端 → 向IdentityServer4发起连接请求
  • IdentityServer4 → 返回成功响应
  • Angular前端 → 向IdentityServer4请求infousers路由
  • IdentityServer4 → 通过IProfileService.GetProfileDataAsync()在Bearer令牌中返回声明
  • 防火墙 → 拦截数据包,检测到令牌过大后截断并重编码
  • Angular前端 → 因HTTP头中JWT令牌不一致出现ERRCONRESET错误

求助问题

  • 是否有开发者遇到过类似的IPS截断JWT的问题?
  • 有无缩减JWT令牌大小的可行方案或思路?
  • 当前Bearer令牌及声明的实现方式是否存在问题?

相关配置

IdentityServer的config.cs

new Client
{
    ClientId = "myClient",
    ClientName = "myClientName",
    AccessTokenType = AccessTokenType.Jwt,
    AllowedGrantTypes = GrantTypes.Implicit,
    AllowAccessTokensViaBrowser = true,
    AlwaysSendClientClaims = true,
    AlwaysIncludeUserClaimsInIdToken = true,
    RequireConsent = false,
    RedirectUris = { urlClient },
    PostLogoutRedirectUris = { urlClient },
    AllowedCorsOrigins = { urlClient },
    AccessTokenLifetime = 86400,
    IdentityTokenLifetime = 86400,
    AllowedScopes =
    {
        IdentityServerConstants.StandardScopes.OpenId,
        IdentityServerConstants.StandardScopes.Profile,
        IdentityServerConstants.StandardScopes.Email,
        SomeConstant,
        SomeConstant,
        SomeConstant,
    }
}

IdentityServer的ConfigureServices()

services.ConfigureNonBreakingSameSiteCookies();
services.AddRazorPages().AddMvcOptions(options => options.EnableEndpointRouting = false).SetCompatibilityVersion(CompatibilityVersion.Latest);
services.AddSingleton(new ConfigurationIdentityServer("myUrl", _Configuration.GetSection("applicationServer").Get<ConfigurationApplicationServer>()));
services.AddSingleton<IResourceOwnerPasswordValidator, ResourceOwnerPasswordValidator>();

var builder = services.AddIdentityServer()
    .AddInMemoryIdentityResources(Config.GetIdentityResources())
    .AddInMemoryApiScopes(Config.GetApiScopes())
    .AddRedirectUriValidator<MyUriValidator>();
builder.Services.AddSingleton<IUserRepository, UserRepository>();
builder.AddProfileService<CustomProfileService>();
builder.AddClientStore<CustomClientStore>();

services.AddScoped<IWireService, WireService>();
services.AddCors(setup => setup.AddDefaultPolicy(b => b.AllowAnyOrigin().AllowAnyHeader().AllowAnyMethod()));

builder.AddCustomTokenRequestValidator<CustomTokenRequestValidator>();
builder.AddDeveloperSigningCredential();

IdentityServer的Configure()

if (env.IsDevelopment())
    app.UseDeveloperExceptionPage();

app.UseStaticFiles();
app.UseCookiePolicy();
app.UseRouting();
app.UseCors();
app.UseIdentityServer();
app.UseMvcWithDefaultRoute();
app.UseAuthentication();

JWT令牌示例

{
  "alg": "RS256",
  "kid": "F5B66993EBF31790213A4D52AD81F98E",
  "typ": "at+jwt"
}
{
  "nbf": 1687784431,
  "exp": 1687870831,
  "iss": "myAuthUrl",
  "client_id": "myClient",
  "sub": "1",
  "auth_time": 1687784425,
  "idp": "local",
  "profile": "Admin Admin",
  "key0": "Admin",
  "key1": "1",
  "key2": "1",
  "key3": "True",
  "nb": "0",
  "jti": "3B8CDF16E4AC8490B5F9C2E0C5D7A6CD",
  "sid": "920D817F645FF497490E6AC9D25D1C67",
  "iat": 1687784431,
  "scope": [
    "openid",
    "profile",
    "email",
    "SomeConstant",
    "SomeConstant",
    "SomeConstant"
  ],
  "amr": [
    "pwd"
  ]
}

感谢各位提供思路!

内容的提问来源于stack exchange,提问作者R1 Tech

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 20:05:08