You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署在IIS上的Duende IdentityServer API请求未授权问题排查

Duende IdentityServer 6.2 部署到IIS后刷新令牌失败问题

环境与配置

  • 按官方文档在Duende IdentityServer 6.2中新增API,使用AccessTokenManagement库的类型化HttpClient,采用Authorization Code流程访问API
  • 本地localhost环境下服务器与客户端运行正常,发布到IIS后API调用失败,但身份认证、令牌交换等其他功能正常(已通过Fiddler验证)
  • API调用流程分为两步:
    1. 使用refresh token调用/connect/token获取新的access token
    2. 使用新的access token调用自定义业务端点
  • 未使用反向代理,采用普通URI;已启用自动密钥管理,密钥存储在开发与生产环境共用的SQL表中;已启用Asp.Net Core Data Protection,密钥也在环境间共用

问题现象

  • 调用流程在第一步失败:调用/connect/token接口返回未授权状态,无法定位具体原因
  • 本地正常请求与IIS部署后的异常请求无明显差异,且此前调用/connect/userinfo的相同刷新流程可正常执行
  • 服务器与客户端日志未提供有效排查线索

关键日志片段

///////异常请求日志片段
|Duende.AccessTokenManagement.OpenIdConnect.UserAccessAccessTokenManagementService|Token for user test@test.com needs refreshing. 
|Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationHandler|AuthenticationScheme: cookie was successfully authenticated. 
|Duende.AccessTokenManagement.OpenIdConnect.UserTokenEndpointService|refresh token request to: https://auth.mysite.org/connect/token 
|Duende.AccessTokenManagement.OpenIdConnect.UserAccessAccessTokenManagementService|Error refreshing access token. Error = Unauthorized 
|System.Net.Http.HttpClient.IdsService.ClientHandler|Sending HTTP request POST https://auth.mysite.org/mycontroller/myaction 
|System.Net.Http.HttpClient.IdsService.ClientHandler|Received HTTP response headers after 117.7278ms - 401 

///////正常请求日志片段
|Duende.AccessTokenManagement.OpenIdConnect.UserAccessAccessTokenManagementService|Token for user test@test.com needs refreshing. 
|Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationHandler|AuthenticationScheme: Cookies was successfully authenticated. 
|Duende.AccessTokenManagement.OpenIdConnect.UserTokenEndpointService|refresh token request to: https://localhost:5001/connect/token 
|Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationHandler|AuthenticationScheme: Cookies signed in. 
|System.Net.Http.HttpClient.IdsService.ClientHandler|Sending HTTP request POST https://localhost:5001/mycontroller/myaction 
|System.Net.Http.HttpClient.IdsService.ClientHandler|Received HTTP response headers after 1994.9611ms - 200

///////异常请求时的服务器日志
Duende.IdentityServer.Hosting.EndpointRouter No endpoint entry found for request path: "/mycontroller/myaction"
Duende.IdentityServer.Hosting.LocalApiAuthentication.LocalApiAuthenticationHandler HandleAuthenticateAsync called
Duende.IdentityServer.Hosting.LocalApiAuthentication.LocalApiAuthenticationHandler AuthenticationScheme: "IdentityServerAccessToken" was not authenticated.
Duende.IdentityServer.Hosting.LocalApiAuthentication.LocalApiAuthenticationHandler AuthenticationScheme: "IdentityServerAccessToken" was challenged.

内容的提问来源于stack exchange,提问作者Niksr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 12:01:07