如何用node-oidc-provider搭建对接Azure AD的认证服务?
搭建Azure AD中间层认证服务器:node-oidc-provider配置疑问与实现需求
我反复查阅node-oidc-provider文档及Stack Overflow相关内容仍无收获,特此求助。我正尝试搭建作为Azure AD与应用中间层的认证服务器(地址如https://auth.<something>.com),让用户通过该服务完成AD登录,无需直接对接Azure AD,最终为开发者提供含API密钥与认证能力的开发平台。
现有疑问:如何基于node-oidc-provider实现该需求?文档基础配置如下:
const app = express(); … const configuration = { clients: [ { client_id: 'oidc_client', client_secret: 'a_different_secret', grant_types: ['authorization_code'], response_types: ['code'], redirect_uris: [] } ] … }; const oidc = new Provider('http://localhost:3000', configuration as any); app.use('/oidc', oidc.callback()); app.listen(3000);
但文档未解决我的问题,具体配置疑问如下:
clients列表是认证服务器对接的身份提供者(如Azure AD),还是接入该服务的客户端?是否需添加Azure AD凭证?
client_id是我的认证服务器ID,还是身份提供者的认证服务器ID?
client_secret是自行生成的密钥、身份提供者密钥,还是客户端密钥?如何生成?
grant_types和response_types是Azure AD支持的类型、服务器提供的类型,还是客户端所需的类型?
redirect_uris是否为客户端在oidc-client中配置的内容?若为认证后重定向地址,能否由客户端动态指定?
我期望接入的客户端可按如下方式实现:
import { Issuer } from 'openid-client'; const authEndpoint = process.env.AUTH_URL; // https://auth.<something>.com const dpIssuer = new Issuer({ issuer: `${authEndpoint}/oidc/`, authorization_endpoint: `${authEndpoint}/oidc/authorize`, token_endpoint: `${authEndpoint}/oidc/token`, userinfo_endpoint: `${authEndpoint}/oidc/userInfo`, end_session_endpoint: `${authEndpoint}/logout` }); export const getClient = (applicationUrl = '') => { const options = { client_id: process.env.CLIENT_ID, // client id provided from my auth server client_secret: process.env.CLIENT_SECRET, // client secret provided from my auth server redirect_uris: [`${applicationUrl}/auth/callback`], // whatever redirect uri they want response_types: ['code'] }; return new dpIssuer.Client(options); };
服务器端示例:
app.get('/auth/login', function (req, res) { const authorizationUrl = getClient('http://localhost:8080').authorizationUrl({ scope: 'email openid profile' }); res.redirect(302, authorizationUrl); });
请问如何实现该需求?若有遗漏请指出。
内容的提问来源于stack exchange,提问作者phun-ky
相关产品推荐
相关产品推荐

