You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用node-oidc-provider搭建对接Azure AD的认证服务?

搭建Azure AD中间层认证服务器:node-oidc-provider配置疑问与实现需求

我反复查阅node-oidc-provider文档及Stack Overflow相关内容仍无收获,特此求助。我正尝试搭建作为Azure AD与应用中间层的认证服务器(地址如https://auth.<something>.com),让用户通过该服务完成AD登录,无需直接对接Azure AD,最终为开发者提供含API密钥与认证能力的开发平台。

现有疑问:如何基于node-oidc-provider实现该需求?文档基础配置如下:

const app = express();
…
const configuration = {
  clients: [
    {
      client_id: 'oidc_client',
      client_secret: 'a_different_secret',
      grant_types: ['authorization_code'],
      response_types: ['code'],
      redirect_uris: []
    }
  ]
…
};

const oidc = new Provider('http://localhost:3000', configuration as any);

app.use('/oidc', oidc.callback());
app.listen(3000);

但文档未解决我的问题,具体配置疑问如下:

    1. clients列表是认证服务器对接的身份提供者(如Azure AD),还是接入该服务的客户端?是否需添加Azure AD凭证?
    1. client_id是我的认证服务器ID,还是身份提供者的认证服务器ID?
    1. client_secret是自行生成的密钥、身份提供者密钥,还是客户端密钥?如何生成?
    1. grant_types和response_types是Azure AD支持的类型、服务器提供的类型,还是客户端所需的类型?
    1. redirect_uris是否为客户端在oidc-client中配置的内容?若为认证后重定向地址,能否由客户端动态指定?

我期望接入的客户端可按如下方式实现:

import { Issuer } from 'openid-client';

const authEndpoint = process.env.AUTH_URL; // https://auth.<something>.com
const dpIssuer = new Issuer({
  issuer: `${authEndpoint}/oidc/`,
  authorization_endpoint: `${authEndpoint}/oidc/authorize`,
  token_endpoint: `${authEndpoint}/oidc/token`,
  userinfo_endpoint: `${authEndpoint}/oidc/userInfo`,
  end_session_endpoint: `${authEndpoint}/logout`
});

export const getClient = (applicationUrl = '') => {
  const options = {
    client_id: process.env.CLIENT_ID, // client id provided from my auth server
    client_secret: process.env.CLIENT_SECRET,  // client secret provided from my auth server
    redirect_uris: [`${applicationUrl}/auth/callback`], // whatever redirect uri they want
    response_types: ['code']
  };

  return new dpIssuer.Client(options);
};

服务器端示例:

app.get('/auth/login', function (req, res) {
  const authorizationUrl = getClient('http://localhost:8080').authorizationUrl({
    scope: 'email openid profile'
  });
  res.redirect(302, authorizationUrl);
});

请问如何实现该需求?若有遗漏请指出。

内容的提问来源于stack exchange,提问作者phun-ky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 15:22:30