You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何无需先从Identity Server 4获取令牌访问.NET Core Web API?

解决方案

一、在Identity Server 4中配置客户端凭证授权类型

你的需求适配IS4原生支持的Client Credentials授权类型,这是专门为客户端级、无用户参与的认证场景设计的方案,可生成客户端专属令牌。

  1. 添加客户端配置
    在IS4的客户端配置代码中,新增一个使用该授权类型的客户端,并配置令牌有效期(按需求设置为极长时长):
new Client
{
    ClientId = "special-client-id",
    ClientName = "专属访问客户端",
    AllowedGrantTypes = GrantTypes.ClientCredentials,
    ClientSecrets = { new Secret("your-secure-client-secret".Sha256()) }, // 客户端密钥需严格保密
    AllowedScopes = { "your-api-resource-scope" }, // 对应Web API的资源作用域
    AccessTokenLifetime = int.MaxValue, // 设置令牌长期有效(生产环境建议设为合理长周期,如1年,再配合刷新机制)
    AllowOfflineAccess = false
}
  1. 预生成固定令牌(可选)
    如果不想让客户端每次请求IS4拿令牌,可在IS4中写一个接口手动生成长期令牌:
[ApiController]
[Route("api/token")]
public class ClientTokenController : ControllerBase
{
    private readonly ITokenService _tokenService;
    private readonly IClientStore _clientStore;
    private readonly IResourceStore _resourceStore;

    public ClientTokenController(ITokenService tokenService, IClientStore clientStore, IResourceStore resourceStore)
    {
        _tokenService = tokenService;
        _clientStore = clientStore;
        _resourceStore = resourceStore;
    }

    [HttpGet("generate")]
    public async Task<IActionResult> GenerateLongLivedToken()
    {
        var client = await _clientStore.FindClientByIdAsync("special-client-id");
        if (client == null) return NotFound("客户端不存在");

        var resources = await _resourceStore.FindResourcesByScopeAsync(client.AllowedScopes);
        var tokenResult = await _tokenService.CreateTokenAsync(new TokenCreationRequest
        {
            ValidatedRequest = new ValidatedTokenRequest
            {
                Client = client,
                RequestedScopes = client.AllowedScopes,
                Resources = resources
            },
            Subject = null, // 客户端凭证无用户主体
            TokenType = OidcConstants.TokenTypes.AccessToken
        });

        return Ok(new { AccessToken = tokenResult.AccessToken });
    }
}

调用该接口即可得到长期有效的客户端令牌,后续客户端直接将其放在Authorization: Bearer {token}请求头中访问API。

二、在.NET 6 Web API中验证令牌

API端需配置为接受IS4颁发的客户端令牌,同时可添加策略限制仅指定客户端访问:

  1. 配置认证与授权服务
    在Program.cs中添加:
builder.Services.AddAuthentication("Bearer")
    .AddJwtBearer("Bearer", options =>
    {
        options.Authority = "https://your-is4-server-url"; // 你的IS4服务器地址
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateAudience = true,
            ValidAudience = "your-api-resource-scope",
            ValidateLifetime = true,
            ClockSkew = TimeSpan.Zero
        };
    });

builder.Services.AddAuthorization(options =>
{
    options.AddPolicy("SpecialClientOnly", policy =>
    {
        policy.RequireAuthenticatedUser();
        policy.RequireClaim(JwtClaimTypes.ClientId, "special-client-id"); // 仅允许指定客户端的令牌访问
    });
});

// 启用认证和授权中间件
app.UseAuthentication();
app.UseAuthorization();
  1. 保护目标接口
    在需要特殊访问的接口上应用自定义策略:
[ApiController]
[Route("api/special")]
[Authorize(Policy = "SpecialClientOnly")]
public class SpecialDataController : ControllerBase
{
    [HttpGet]
    public IActionResult GetData()
    {
        return Ok("仅专属客户端可访问的数据");
    }
}

三、关键安全注意事项

  • 客户端密钥和预生成的令牌绝对不能硬编码在前端代码中,需通过后端配置、环境变量或安全配置中心管理。
  • 即使需求是长期有效,也不建议设置AccessTokenLifetime为int.MaxValue,建议设为1年左右,同时启用刷新令牌机制定期更新,降低令牌泄露后的风险。
  • 可在API端添加IP白名单限制,仅允许指定IP段的请求访问该特殊接口。
  • 必须全程启用HTTPS,防止令牌在传输过程中被窃取。

内容的提问来源于stack exchange,提问作者G.Dimov

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 15:55:31