You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core Identity Server 登出功能失效问题求助

问题:Identity Server生产环境登出功能异常,本地环境正常

执行登出操作后,系统跳转至首页,但实际并未完成登出。操作流程:点击登出按钮跳转至Identity Server页面并提示“已登出”,点击返回链接后回到客户端首页,而非预期的登录页面。本地环境下登出功能正常,生产环境中异常。

客户端Startup配置代码

builder.Services.AddAuthentication(options =>
    {
        options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        options.DefaultChallengeScheme = "oidc";
    })
    .AddCookie(options =>
    {
        options.Cookie.Name = IdentityConstants.ApplicationScheme;
        options.ExpireTimeSpan = TimeSpan.FromMinutes(1);
        options.LogoutPath = "/Home/Logout";
    })
    .AddOpenIdConnect("oidc", options =>
    {
        options.SignInScheme = "Cookies";

        options.Authority = builder.Environment.IsDevelopment() ? appSetting.Development.IdentityServerUrl : appSetting.Production.IdentityServerUrl;
        options.RequireHttpsMetadata = false;

        options.ClientId = "technosys-inv-ui";
        options.ClientSecret = "technosys-inv-secret";
        options.ResponseType = "code id_token";

        options.SaveTokens = true;
        options.GetClaimsFromUserInfoEndpoint = true;

        options.Scope.Add("technosys-inv-api");
        options.ClaimActions.MapJsonKey("website", "website");
    });

builder.Services.ConfigureApplicationCookie(options =>
{
    options.Cookie.IsEssential = true;
    options.Cookie.SameSite = SameSiteMode.Unspecified;
});

客户端登出Action代码

[AllowAnonymous]
public async Task Logout()
{
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme, new AuthenticationProperties
    {
        RedirectUri = "/"
    });
}

Identity Server端客户端配置代码

public static IEnumerable<Client> GetClients(IConfiguration configuration)
{
    AppSettings appSettings = configuration.GetSection("AppSettings").Get<AppSettings>();
    AppSetting appSetting = null;
    if (appSettings.Environment == "Development")
        appSetting = appSettings.Development;
    else
        appSetting = appSettings.Production;

    return new[]
    {
        // client credentials flow client
        new Client
        {
            ClientId = "technosys-inv-ui",
            ClientName = "Technosys Inventory UI",
            RedirectUris = { appSetting.AdminClientUrl + "signin-oidc" },
            PostLogoutRedirectUris = { appSetting.AdminClientUrl },
            FrontChannelLogoutUri = appSetting.AdminClientUrl + "signout-oidc",
            AllowedGrantTypes = GrantTypes.Hybrid,
            ClientSecrets = { new Secret("technosys-inv-secret".ToSha256()) },
            AllowOfflineAccess = true,
            AllowedScopes = { "technosys-inv-api", "openid","profile" },
            RequireConsent = false,
        }
    };
}

解决方案

1. 完善登出逻辑,同时签出OIDC Scheme

当前登出仅清除了客户端本地Cookie,未触发Identity Server的全局登出流程。修改登出Action:

[AllowAnonymous]
public async Task Logout()
{
    // 清除客户端本地认证Cookie
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
    // 触发OIDC登出,通知Identity Server销毁用户会话
    await HttpContext.SignOutAsync("oidc", new AuthenticationProperties
    {
        RedirectUri = "/"
    });
}

2. 修正生产环境HTTPS相关配置

生产环境必须启用HTTPS,调整OIDC配置:

options.RequireHttpsMetadata = !builder.Environment.IsDevelopment(); // 生产环境设为true

3. 调整Cookie的SameSite和Secure策略

生产环境下跨域场景需配置正确的Cookie属性:

builder.Services.ConfigureApplicationCookie(options =>
{
    options.Cookie.IsEssential = true;
    options.Cookie.SameSite = builder.Environment.IsDevelopment() ? SameSiteMode.Unspecified : SameSiteMode.None;
    options.Cookie.SecurePolicy = builder.Environment.IsDevelopment() ? CookieSecurePolicy.SameAsRequest : CookieSecurePolicy.Always;
});

4. 验证PostLogoutRedirectUris和FrontChannelLogoutUri的正确性

  • 确认生产环境的appSetting.AdminClientUrl是完整的HTTPS地址,无拼写错误
  • 若FrontChannelLogout在生产环境无法正常回调(如防火墙限制),可暂时注释FrontChannelLogoutUri配置,测试登出是否正常,再排查回调连通性问题

5. 检查Identity Server会话配置

确保Identity Server生产环境的会话Cookie配置正确,启用Secure和合适的SameSite模式,避免会话未正确销毁。

内容的提问来源于stack exchange,提问作者Nishan Dhungana

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.09 14:40:36