Duende IdentityServer EndSession不应弹出确认提示的异常问题
问题描述
调用EndSession端点实现登出后重定向回站点时遇到异常:
- 已传入
id_token_hint和post_logout_redirect_uri参数,日志显示请求验证成功 - 实际仍弹出登出确认提示,点击确认后无重定向链接,参数仿佛被忽略
- 使用版本:
Microsoft.AspNetCore.ApiAuthorization.IdentityServer 6.0.18(依赖Duende.IdentityServer 5.2.0) - 关闭响应压缩后消除了浏览器刷新中间件的警告,但问题未解决
相关日志:
info: Duende.IdentityServer.Validation.EndSessionRequestValidator[0] End session request validation success { "ClientId": "onecalc-webapp", "ClientName": "OneCalc Webapp", "SubjectId": "unknown", "PostLogOutUri": "https://localhost:3001/logout", "Raw": { "id_token_hint": "<em><strong>REDACTED</strong></em>", "post_logout_redirect_uri": "https://localhost:3001/logout" } } warn: Microsoft.AspNetCore.Watch.BrowserRefresh.BrowserRefreshMiddleware[4] Unable to configure browser refresh script injection on the response. This may have been caused by the response's Content-Encoding: 'br'. Consider disabling response compression.
解决方案
1. 检查客户端PostLogoutRedirectUris配置
确保在IdentityServer的客户端配置中,PostLogoutRedirectUris列表已明确包含你的重定向地址https://localhost:3001/logout:
// 示例客户端配置 new Client { ClientId = "onecalc-webapp", ClientName = "OneCalc Webapp", // 其他配置... PostLogoutRedirectUris = new List<string> { "https://localhost:3001/logout" } }
即使参数验证通过,若客户端未配置该地址,IdentityServer会拒绝自动重定向。
2. 处理SubjectId为unknown的异常
日志中SubjectId显示为unknown,说明id_token_hint未正确关联到当前登录会话:
- 确认
id_token_hint是用户登录时获取的有效ID Token(未过期、签名有效) - 确保调用EndSession端点时,用户仍处于登录状态(存在有效会话)
3. 配置自动跳过登出确认提示
默认情况下,IdentityServer会要求用户确认登出。若需自动完成登出并重定向,可通过两种方式配置:
方式一:修改客户端配置
给客户端添加RequireLogoutPrompt = false:
new Client { ClientId = "onecalc-webapp", // 其他配置... RequireLogoutPrompt = false }
方式二:自定义登出页面逻辑
若使用默认的登出页面,可修改页面代码,在验证请求有效时自动触发重定向:
@page "/Account/Logout" @inject SignInManager<IdentityUser> SignInManager @inject IIdentityServerInteractionService InteractionService @functions { protected override async Task OnInitializedAsync() { var logoutId = Request.Query["logoutId"]; var logoutContext = await InteractionService.GetLogoutContextAsync(logoutId); // 若存在有效的PostLogoutRedirectUri,自动登出并重定向 if (!string.IsNullOrEmpty(logoutContext.PostLogoutRedirectUri)) { await SignInManager.SignOutAsync(); Response.Redirect(logoutContext.PostLogoutRedirectUri); } } }
4. 检查ApiAuthorization的特殊配置
使用Microsoft.AspNetCore.ApiAuthorization.IdentityServer时,需确保AddApiAuthorization的配置正确关联客户端:
services.AddApiAuthorization() .AddClient("onecalc-webapp", options => { options.PostLogoutRedirectUri = "https://localhost:3001/logout"; });
内容的提问来源于stack exchange,提问作者Leo
相关产品推荐
相关产品推荐

