ASP.NET Core Identity Server 登出功能失效问题求助
问题:Identity Server生产环境登出功能异常,本地环境正常
执行登出操作后,系统跳转至首页,但实际并未完成登出。操作流程:点击登出按钮跳转至Identity Server页面并提示“已登出”,点击返回链接后回到客户端首页,而非预期的登录页面。本地环境下登出功能正常,生产环境中异常。
客户端Startup配置代码
builder.Services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = "oidc"; }) .AddCookie(options => { options.Cookie.Name = IdentityConstants.ApplicationScheme; options.ExpireTimeSpan = TimeSpan.FromMinutes(1); options.LogoutPath = "/Home/Logout"; }) .AddOpenIdConnect("oidc", options => { options.SignInScheme = "Cookies"; options.Authority = builder.Environment.IsDevelopment() ? appSetting.Development.IdentityServerUrl : appSetting.Production.IdentityServerUrl; options.RequireHttpsMetadata = false; options.ClientId = "technosys-inv-ui"; options.ClientSecret = "technosys-inv-secret"; options.ResponseType = "code id_token"; options.SaveTokens = true; options.GetClaimsFromUserInfoEndpoint = true; options.Scope.Add("technosys-inv-api"); options.ClaimActions.MapJsonKey("website", "website"); }); builder.Services.ConfigureApplicationCookie(options => { options.Cookie.IsEssential = true; options.Cookie.SameSite = SameSiteMode.Unspecified; });
客户端登出Action代码
[AllowAnonymous] public async Task Logout() { await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme, new AuthenticationProperties { RedirectUri = "/" }); }
Identity Server端客户端配置代码
public static IEnumerable<Client> GetClients(IConfiguration configuration) { AppSettings appSettings = configuration.GetSection("AppSettings").Get<AppSettings>(); AppSetting appSetting = null; if (appSettings.Environment == "Development") appSetting = appSettings.Development; else appSetting = appSettings.Production; return new[] { // client credentials flow client new Client { ClientId = "technosys-inv-ui", ClientName = "Technosys Inventory UI", RedirectUris = { appSetting.AdminClientUrl + "signin-oidc" }, PostLogoutRedirectUris = { appSetting.AdminClientUrl }, FrontChannelLogoutUri = appSetting.AdminClientUrl + "signout-oidc", AllowedGrantTypes = GrantTypes.Hybrid, ClientSecrets = { new Secret("technosys-inv-secret".ToSha256()) }, AllowOfflineAccess = true, AllowedScopes = { "technosys-inv-api", "openid","profile" }, RequireConsent = false, } }; }
解决方案
1. 完善登出逻辑,同时签出OIDC Scheme
当前登出仅清除了客户端本地Cookie,未触发Identity Server的全局登出流程。修改登出Action:
[AllowAnonymous] public async Task Logout() { // 清除客户端本地认证Cookie await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme); // 触发OIDC登出,通知Identity Server销毁用户会话 await HttpContext.SignOutAsync("oidc", new AuthenticationProperties { RedirectUri = "/" }); }
2. 修正生产环境HTTPS相关配置
生产环境必须启用HTTPS,调整OIDC配置:
options.RequireHttpsMetadata = !builder.Environment.IsDevelopment(); // 生产环境设为true
3. 调整Cookie的SameSite和Secure策略
生产环境下跨域场景需配置正确的Cookie属性:
builder.Services.ConfigureApplicationCookie(options => { options.Cookie.IsEssential = true; options.Cookie.SameSite = builder.Environment.IsDevelopment() ? SameSiteMode.Unspecified : SameSiteMode.None; options.Cookie.SecurePolicy = builder.Environment.IsDevelopment() ? CookieSecurePolicy.SameAsRequest : CookieSecurePolicy.Always; });
4. 验证PostLogoutRedirectUris和FrontChannelLogoutUri的正确性
- 确认生产环境的
appSetting.AdminClientUrl是完整的HTTPS地址,无拼写错误 - 若FrontChannelLogout在生产环境无法正常回调(如防火墙限制),可暂时注释
FrontChannelLogoutUri配置,测试登出是否正常,再排查回调连通性问题
5. 检查Identity Server会话配置
确保Identity Server生产环境的会话Cookie配置正确,启用Secure和合适的SameSite模式,避免会话未正确销毁。
内容的提问来源于stack exchange,提问作者Nishan Dhungana
相关产品推荐
相关产品推荐

