You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor WASM集成OIDC:生产环境API调用报500,调试正常

问题分析:Blazor WASM生产环境API请求500错误(IDX20803)

问题背景

调试阶段登录后可正常获取令牌并收发API请求,但发布到生产环境后,所有带[Authorize]的API请求返回500错误,客户端抛出未处理异常,服务器日志报IDX20803错误。

相关配置代码

WASM端配置

builder.Services.AddOidcAuthentication(opt =>
   {
       opt.ProviderOptions.Authority = "https://xx.yy.pl/auth/realms/corporate";
       opt.ProviderOptions.ClientId = "#ClienID";
       opt.ProviderOptions.ResponseType = "code";
   });

var IHttpServiceClient = builder.Services.AddHttpClient<IBaseHttpService,BaseHttpService>((serviceProvider, client) =>
{
    client.BaseAddress = new Uri(builder.HostEnvironment.BaseAddress);
});
builder.Services.AddScoped<CustomAuthorizationMessageHandler>();
IHttpServiceClient.AddHttpMessageHandler<CustomAuthorizationMessageHandler>();

CustomAuthorizationMessageHandler实现

public class CustomAuthorizationMessageHandler:AuthorizationMessageHandler
{
    public CustomAuthorizationMessageHandler(IAccessTokenProvider provider , NavigationManager nav) :base(provider, nav)
    {
        ConfigureHandler(authorizedUrls: new[] { nav.BaseUri });
    }
}

服务器API端认证配置

builder.Services
    .AddAuthentication("Bearer")
    .AddJwtBearer("Bearer", options =>
    {      
        options.Authority = "https://xx.yy.pl/auth/realms/corporate";
        options.TokenValidationParameters.ValidateAudience = false;
    });
    builder.Services.AddAuthorization(options =>
    {
        var defaultAuthorizationPolicyBuilder = new AuthorizationPolicyBuilder(JwtBearerDefaults.AuthenticationScheme);
        defaultAuthorizationPolicyBuilder = defaultAuthorizationPolicyBuilder.RequireAuthenticatedUser();
        options.DefaultPolicy = defaultAuthorizationPolicyBuilder.Build();
    }); 

错误信息

客户端异常日志

Unhandled exception rendering component: 
System.Exception
   at Web.Client.Core.HttpClients.BaseHttpService.<sendRequest>d__11`1[[Web.Shared.WeatherForecast[], Web.Shared, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]].MoveNext()
   at Web.Client.Core.HttpClients.BaseHttpService.<Get>d__5`1[[Web.Shared.WeatherForecast[], Web.Shared, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]].MoveNext()
   at Web.Client.Pages.Learn.FetchData3.OnInitializedAsync()
   at Microsoft.AspNetCore.Components.ComponentBase.RunInitAndSetParametersAsync()
   at Microsoft.AspNetCore.Components.RenderTree.Renderer.GetErrorHandledTask(Task , ComponentState )

服务器端核心错误日志

Microsoft.AspNetCore.Server.IIS.Core.IISHttpServer 
Connection ID "14987979565794590827", Request ID "8000006c-0001-d000-b63f-84710c7967bb": An unhandled exception was thrown by the application.
IDX20803: Unable to obtain configuration from: '[PII of type 'System.String' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.

Microsoft.AspNetCore.Authentication.JwtBearer.JwtBearerHandler
Exception occurred while processing message.
IDX20803: Unable to obtain configuration from: '[PII of type 'System.String' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.

原因分析与解决方案

IDX20803错误的核心是API服务器无法从OIDC权威服务器获取配置信息,调试正常生产异常,主要排查以下方向:

  1. 生产环境网络连通性问题

    • 检查生产API服务器的防火墙/网络策略,确保允许访问OIDC权威地址的配置端点:https://xx.yy.pl/auth/realms/corporate/.well-known/openid-configuration
    • 验证生产服务器的DNS解析是否正常,无代理拦截出站请求
  2. 启用PII日志暴露真实错误
    隐藏的PII信息会掩盖具体错误细节,在API服务器的Program.cs中添加以下代码,显示完整错误内容:

    using Microsoft.IdentityModel.Logging;
    
    // 在builder.Build()之前添加
    IdentityModelEventSource.ShowPII = true;
    

    重新部署后可查看无法获取配置的具体地址、HTTP状态码或SSL错误等信息

  3. SSL证书信任问题

    • 若OIDC服务器使用自签名证书,生产API服务器可能未信任该证书,导致请求失败
    • 解决:将OIDC服务器的根证书导入生产服务器的受信任根证书存储
  4. OIDC配置细节校验

    • 确认API端options.Authority地址与WASM端完全一致,末尾不要添加斜杠
    • 检查OIDC服务器的corporate realm是否存在且配置正常,确保配置端点可正常访问
  5. 反向代理拦截问题
    若API服务器部署在反向代理(如Nginx、IIS ARR)后,需确保代理未修改请求头、未拦截到OIDC服务器的出站请求,必要时配置代理允许访问OIDC地址

验证步骤

  1. 在生产API服务器上,用curl或Postman直接访问OIDC配置端点,确认能返回正常JSON配置
  2. 启用PII日志后,根据具体错误信息定位问题根源
  3. 验证SSL证书信任状态与网络连通性

内容的提问来源于stack exchange,提问作者Dorian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.24 16:04:57