You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ABP Framework 7.0新增JwtBearer获取token遇invalid_scope问题求助

问题排查:OpenIddict返回invalid_scope错误

核心原因

你请求的Visit scope没有在认证服务器(AuthServer)的OpenIddict配置中注册,或者你的客户端未被授权使用该scope。这个错误和Host模块里新增的jwt2认证方案无关——认证方案负责验证token,而token的生成规则(包括允许的scope)完全由认证服务器管控。

解决步骤

1. 在AuthServer中注册Visit Scope

找到你的AuthServer项目(通常命名为*.AuthServer),按以下方式添加Visit scope:

方式一:静态代码配置

如果你的AuthServer用静态代码定义scope,在ConfigureServices的OpenIddict服务器配置里添加AddScopes("Visit"):

context.Services.AddOpenIddict()
    .AddCore(options =>
    {
        // 你的Core配置...
    })
    .AddServer(options =>
    {
        options
            .SetAuthorizationEndpointUris("/connect/authorize")
            .SetTokenEndpointUris("/connect/token")
            // 其他服务器配置...
            // 新增Visit scope
            .AddScopes("Visit");
    });

方式二:数据库存储配置(ABP默认推荐)

如果用数据库存储OpenIddict数据,在种子数据类中添加Visit scope:

// 例如在YourProjectNameAuthServerDbMigrationService或自定义种子类中
var visitScope = new OpenIddictScope
{
    Id = Guid.NewGuid().ToString(),
    Name = "Visit",
    DisplayName = "外部接口访问权限",
    Description = "用于标识可被外部请求访问的接口权限"
};

await _dbContext.Scopes.AddAsync(visitScope);
await _dbContext.SaveChangesAsync();

2. 授权客户端使用Visit Scope

确保你在Postman中使用的客户端ID,已被AuthServer允许使用Visit scope:
在客户端的种子数据配置中,将Visit加入AllowedScopes列表:

var client = new OpenIddictClient
{
    ClientId = "your-postman-client-id",
    ClientSecret = "your-client-secret",
    // 其他客户端配置(如AllowedGrantTypes、RedirectUris等)...
    AllowedScopes = { "openid", "profile", "MyProjectName", "Visit" } // 新增Visit
};

await _dbContext.Clients.AddAsync(client);
await _dbContext.SaveChangesAsync();

3. 重新请求Token

重启AuthServer后,在Postman的token请求中,将scope参数设置为包含Visit(如果需要保留原有权限,用空格分隔多个scope):

scope=MyProjectName Visit

额外说明

你Host模块中的jwt2认证方案,作用是验证携带Visit scope的token,不需要修改它的配置。只要生成的token包含Visit scope,且符合jwt2的验证规则(Authority、Audience等),就能通过my_jwt2策略的授权。

内容的提问来源于stack exchange,提问作者Jesus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 08:57:40