按教程配置Node.js+Express的Auth0登录端点后无法正常工作
问题:Node.js + Express 集成 Auth0 时登录端点报错
Issuer.discover() failed 代码示例
const { auth } = require('express-openid-connect'); const express = require('express'); const config = { authRequired: false, auth0Logout: true, secret: 'secret', baseURL: 'https://3803-188-124-153-232.ngrok.io', clientID: '', issuerBaseURL: '' }; const app = express(); // auth router attaches /login, /logout, and /callback routes to the baseURL app.use(auth(config)); // req.isAuthenticated is provided from the auth router app.get('/', (req, res) => { console.log(req.oidc.isAuthenticated()); res.send("hello"); }); app.listen(3000)
报错信息
AggregateError: Issuer.discover() failed. OPError: expected 200 OK with body but no body was returned OPError: expected 200 OK, got: 404 Not Found
背景说明
最初使用localhost:3000作为baseURL,遇到问题后改用ngrok转发到localhost:3000,但两次尝试均失败。已反复检查baseURL、clientID和issuerBaseURL的正确性,仍不清楚报错原因及解决方法。
解决方法
- 确认
issuerBaseURL格式正确:必须是你的Auth0租户域名,格式为https://<你的租户名>.auth0.com,不能遗漏https://协议头,也不要在末尾加斜杠。 - 检查Auth0租户配置:
- 登录Auth0控制台,进入「应用程序 > 常规」页面,确保
clientID完全复制正确,无多余空格或字符。 - 确认「允许的回调URL」已添加
baseURL + /callback,比如https://3803-188-124-153-232.ngrok.io/callback。 - 确认「允许的注销URL」已添加你的baseURL,比如
https://3803-188-124-153-232.ngrok.io。
- 登录Auth0控制台,进入「应用程序 > 常规」页面,确保
- 验证网络连通性:
- 确保ngrok隧道处于活跃状态,直接访问你的ngrok URL能正常返回Express首页的"hello"。
- 本地执行
curl https://<你的租户名>.auth0.com/.well-known/openid-configuration,确认能返回正常的JSON配置,排除防火墙或代理拦截问题。
- 更新依赖版本:执行
npm update express-openid-connect,确保使用最新稳定版本的express-openid-connect,避免版本兼容问题。 - 替换临时
secret:代码中secret: 'secret'是临时值,生产环境需替换为32位以上的复杂随机字符串,当前报错虽与此无关,但需注意后续安全性。
内容的提问来源于stack exchange,提问作者Elias Knudsen
相关产品推荐
相关产品推荐

