JWT令牌过大触发防火墙IPS拦截问题求助(附配置)
JWT令牌过大被IPS防火墙截断导致前端ERRCONRESET问题求助
我们采用Angular前端+IdentityServer4认证服务架构,认证完成后前端会调用用户信息接口,该接口通过HTTP请求头中的Bearer令牌返回用户声明。但在启用IPS(入侵防御系统,如Stormshield、Palo alto、Azure)的部分防火墙环境下,因JWT令牌内容超过1000字节被截断重编码,导致前端出现ERRCONRESET错误。
流程总结
- Angular前端 → 向IdentityServer4发起连接请求
- IdentityServer4 → 返回成功响应
- Angular前端 → 向IdentityServer4请求infousers路由
- IdentityServer4 → 通过
IProfileService.GetProfileDataAsync()在Bearer令牌中返回声明 - 防火墙 → 拦截数据包,检测到令牌过大后截断并重编码
- Angular前端 → 因HTTP头中JWT令牌不一致出现ERRCONRESET错误
求助问题
- 是否有开发者遇到过类似的IPS截断JWT的问题?
- 有无缩减JWT令牌大小的可行方案或思路?
- 当前Bearer令牌及声明的实现方式是否存在问题?
相关配置
IdentityServer的config.cs
new Client { ClientId = "myClient", ClientName = "myClientName", AccessTokenType = AccessTokenType.Jwt, AllowedGrantTypes = GrantTypes.Implicit, AllowAccessTokensViaBrowser = true, AlwaysSendClientClaims = true, AlwaysIncludeUserClaimsInIdToken = true, RequireConsent = false, RedirectUris = { urlClient }, PostLogoutRedirectUris = { urlClient }, AllowedCorsOrigins = { urlClient }, AccessTokenLifetime = 86400, IdentityTokenLifetime = 86400, AllowedScopes = { IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, IdentityServerConstants.StandardScopes.Email, SomeConstant, SomeConstant, SomeConstant, } }
IdentityServer的ConfigureServices()
services.ConfigureNonBreakingSameSiteCookies(); services.AddRazorPages().AddMvcOptions(options => options.EnableEndpointRouting = false).SetCompatibilityVersion(CompatibilityVersion.Latest); services.AddSingleton(new ConfigurationIdentityServer("myUrl", _Configuration.GetSection("applicationServer").Get<ConfigurationApplicationServer>())); services.AddSingleton<IResourceOwnerPasswordValidator, ResourceOwnerPasswordValidator>(); var builder = services.AddIdentityServer() .AddInMemoryIdentityResources(Config.GetIdentityResources()) .AddInMemoryApiScopes(Config.GetApiScopes()) .AddRedirectUriValidator<MyUriValidator>(); builder.Services.AddSingleton<IUserRepository, UserRepository>(); builder.AddProfileService<CustomProfileService>(); builder.AddClientStore<CustomClientStore>(); services.AddScoped<IWireService, WireService>(); services.AddCors(setup => setup.AddDefaultPolicy(b => b.AllowAnyOrigin().AllowAnyHeader().AllowAnyMethod())); builder.AddCustomTokenRequestValidator<CustomTokenRequestValidator>(); builder.AddDeveloperSigningCredential();
IdentityServer的Configure()
if (env.IsDevelopment()) app.UseDeveloperExceptionPage(); app.UseStaticFiles(); app.UseCookiePolicy(); app.UseRouting(); app.UseCors(); app.UseIdentityServer(); app.UseMvcWithDefaultRoute(); app.UseAuthentication();
JWT令牌示例
{ "alg": "RS256", "kid": "F5B66993EBF31790213A4D52AD81F98E", "typ": "at+jwt" } { "nbf": 1687784431, "exp": 1687870831, "iss": "myAuthUrl", "client_id": "myClient", "sub": "1", "auth_time": 1687784425, "idp": "local", "profile": "Admin Admin", "key0": "Admin", "key1": "1", "key2": "1", "key3": "True", "nb": "0", "jti": "3B8CDF16E4AC8490B5F9C2E0C5D7A6CD", "sid": "920D817F645FF497490E6AC9D25D1C67", "iat": 1687784431, "scope": [ "openid", "profile", "email", "SomeConstant", "SomeConstant", "SomeConstant" ], "amr": [ "pwd" ] }
感谢各位提供思路!
内容的提问来源于stack exchange,提问作者R1 Tech
相关产品推荐
相关产品推荐

