You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenIddict中/userinfo端点控制器未执行但API返回响应的问题

问题分析与解决方案

你的自定义UserInfoController未执行,核心原因是OpenIddict服务器默认会自动处理/connect/userinfo端点请求,直接从Access Token中提取基础声明(sub、iss、aud)返回,不会将请求转发到你的自定义控制器。

要让自定义控制器接管UserInfo端点的处理逻辑,需在OpenIddict的服务器配置中启用UserInfo端点的透传(Passthrough)功能。

修改步骤

在Program.cs的AddServer配置块中,添加.EnableUserinfoEndpointPassthrough():

options
    .UseAspNetCore()
    .EnableTokenEndpointPassthrough()
    .EnableAuthorizationEndpointPassthrough()
    .EnableUserinfoEndpointPassthrough(); // 新增该配置项

修改后的完整服务器配置片段:

.AddServer(options =>
{
    options
        .AllowClientCredentialsFlow()
        .AllowAuthorizationCodeFlow()
            .RequireProofKeyForCodeExchange()
        .AllowPasswordFlow()
        .AllowRefreshTokenFlow();
    options.SetTokenEndpointUris("/token")
    .SetAuthorizationEndpointUris("/connect/authorize")
    .SetUserinfoEndpointUris("/connect/userinfo")
    .SetVerificationEndpointUris("/connect/verify");

    // 证书配置部分省略...

    options.SetAccessTokenLifetime(TimeSpan.FromSeconds(60));
    options.SetRefreshTokenLifetime(TimeSpan.FromDays(60));
    options.RegisterScopes(Scopes.Email ,Scopes.Profile, Scopes.Roles, Scopes.OfflineAccess);

    options
            .UseAspNetCore()
            .EnableTokenEndpointPassthrough()
            .EnableAuthorizationEndpointPassthrough()
            .EnableUserinfoEndpointPassthrough(); // 新增的透传配置
}

补充说明

启用透传后,OpenIddict会将/connect/userinfo的请求转发到你的UserInfoController,此时控制器内的自定义逻辑会正常执行:

  • 若请求的Access Token包含email、roles等scope,会返回对应用户声明
  • 若用户不存在,会返回你定义的无效Token错误

内容的提问来源于stack exchange,提问作者Stanley

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 22:40:44