OpenIddict中/userinfo端点控制器未执行但API返回响应的问题
问题分析与解决方案
你的自定义UserInfoController未执行,核心原因是OpenIddict服务器默认会自动处理/connect/userinfo端点请求,直接从Access Token中提取基础声明(sub、iss、aud)返回,不会将请求转发到你的自定义控制器。
要让自定义控制器接管UserInfo端点的处理逻辑,需在OpenIddict的服务器配置中启用UserInfo端点的透传(Passthrough)功能。
修改步骤
在Program.cs的AddServer配置块中,添加.EnableUserinfoEndpointPassthrough():
options .UseAspNetCore() .EnableTokenEndpointPassthrough() .EnableAuthorizationEndpointPassthrough() .EnableUserinfoEndpointPassthrough(); // 新增该配置项
修改后的完整服务器配置片段:
.AddServer(options => { options .AllowClientCredentialsFlow() .AllowAuthorizationCodeFlow() .RequireProofKeyForCodeExchange() .AllowPasswordFlow() .AllowRefreshTokenFlow(); options.SetTokenEndpointUris("/token") .SetAuthorizationEndpointUris("/connect/authorize") .SetUserinfoEndpointUris("/connect/userinfo") .SetVerificationEndpointUris("/connect/verify"); // 证书配置部分省略... options.SetAccessTokenLifetime(TimeSpan.FromSeconds(60)); options.SetRefreshTokenLifetime(TimeSpan.FromDays(60)); options.RegisterScopes(Scopes.Email ,Scopes.Profile, Scopes.Roles, Scopes.OfflineAccess); options .UseAspNetCore() .EnableTokenEndpointPassthrough() .EnableAuthorizationEndpointPassthrough() .EnableUserinfoEndpointPassthrough(); // 新增的透传配置 }
补充说明
启用透传后,OpenIddict会将/connect/userinfo的请求转发到你的UserInfoController,此时控制器内的自定义逻辑会正常执行:
- 若请求的Access Token包含
email、roles等scope,会返回对应用户声明 - 若用户不存在,会返回你定义的无效Token错误
内容的提问来源于stack exchange,提问作者Stanley
相关产品推荐
相关产品推荐

