You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Duende IdentityServer EndSession不应弹出确认提示的异常问题

问题描述

调用EndSession端点实现登出后重定向回站点时遇到异常:

  • 已传入id_token_hint和post_logout_redirect_uri参数,日志显示请求验证成功
  • 实际仍弹出登出确认提示,点击确认后无重定向链接,参数仿佛被忽略
  • 使用版本:Microsoft.AspNetCore.ApiAuthorization.IdentityServer 6.0.18(依赖Duende.IdentityServer 5.2.0)
  • 关闭响应压缩后消除了浏览器刷新中间件的警告,但问题未解决

相关日志:

info: Duende.IdentityServer.Validation.EndSessionRequestValidator[0]
End session request validation success
{
"ClientId": "onecalc-webapp",
"ClientName": "OneCalc Webapp",
"SubjectId": "unknown",
"PostLogOutUri": "https://localhost:3001/logout",
"Raw": {
"id_token_hint": "<em><strong>REDACTED</strong></em>",
"post_logout_redirect_uri": "https://localhost:3001/logout"
}
}

warn: Microsoft.AspNetCore.Watch.BrowserRefresh.BrowserRefreshMiddleware[4]
Unable to configure browser refresh script injection on the response. This may have been caused by the response's Content-Encoding: 'br'. Consider disabling response compression.
解决方案

1. 检查客户端PostLogoutRedirectUris配置

确保在IdentityServer的客户端配置中,PostLogoutRedirectUris列表已明确包含你的重定向地址https://localhost:3001/logout:

// 示例客户端配置
new Client
{
    ClientId = "onecalc-webapp",
    ClientName = "OneCalc Webapp",
    // 其他配置...
    PostLogoutRedirectUris = new List<string>
    {
        "https://localhost:3001/logout"
    }
}

即使参数验证通过,若客户端未配置该地址,IdentityServer会拒绝自动重定向。

2. 处理SubjectId为unknown的异常

日志中SubjectId显示为unknown,说明id_token_hint未正确关联到当前登录会话:

  • 确认id_token_hint是用户登录时获取的有效ID Token(未过期、签名有效)
  • 确保调用EndSession端点时,用户仍处于登录状态(存在有效会话)

3. 配置自动跳过登出确认提示

默认情况下,IdentityServer会要求用户确认登出。若需自动完成登出并重定向,可通过两种方式配置:

方式一:修改客户端配置

给客户端添加RequireLogoutPrompt = false:

new Client
{
    ClientId = "onecalc-webapp",
    // 其他配置...
    RequireLogoutPrompt = false
}

方式二:自定义登出页面逻辑

若使用默认的登出页面,可修改页面代码,在验证请求有效时自动触发重定向:

@page "/Account/Logout"
@inject SignInManager<IdentityUser> SignInManager
@inject IIdentityServerInteractionService InteractionService

@functions {
    protected override async Task OnInitializedAsync()
    {
        var logoutId = Request.Query["logoutId"];
        var logoutContext = await InteractionService.GetLogoutContextAsync(logoutId);
        
        // 若存在有效的PostLogoutRedirectUri,自动登出并重定向
        if (!string.IsNullOrEmpty(logoutContext.PostLogoutRedirectUri))
        {
            await SignInManager.SignOutAsync();
            Response.Redirect(logoutContext.PostLogoutRedirectUri);
        }
    }
}

4. 检查ApiAuthorization的特殊配置

使用Microsoft.AspNetCore.ApiAuthorization.IdentityServer时,需确保AddApiAuthorization的配置正确关联客户端:

services.AddApiAuthorization()
    .AddClient("onecalc-webapp", options =>
    {
        options.PostLogoutRedirectUri = "https://localhost:3001/logout";
    });

内容的提问来源于stack exchange,提问作者Leo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.19 02:13:00