You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

按教程配置Node.js+Express的Auth0登录端点后无法正常工作

问题:Node.js + Express 集成 Auth0 时登录端点报错 Issuer.discover() failed

代码示例

const { auth } = require('express-openid-connect');
const express = require('express');
const config = {
    authRequired: false,
    auth0Logout: true,
    secret: 'secret',
    baseURL: 'https://3803-188-124-153-232.ngrok.io',
    clientID: '',
    issuerBaseURL: ''
};
const app = express();

// auth router attaches /login, /logout, and /callback routes to the baseURL
app.use(auth(config));

// req.isAuthenticated is provided from the auth router
app.get('/', (req, res) => {
    console.log(req.oidc.isAuthenticated());
    res.send("hello");
});

app.listen(3000)

报错信息

AggregateError: Issuer.discover() failed.
    OPError: expected 200 OK with body but no body was returned
    OPError: expected 200 OK, got: 404 Not Found

背景说明

最初使用localhost:3000作为baseURL,遇到问题后改用ngrok转发到localhost:3000,但两次尝试均失败。已反复检查baseURL、clientID和issuerBaseURL的正确性,仍不清楚报错原因及解决方法。


解决方法
  • 确认issuerBaseURL格式正确:必须是你的Auth0租户域名,格式为https://<你的租户名>.auth0.com,不能遗漏https://协议头,也不要在末尾加斜杠。
  • 检查Auth0租户配置:
    • 登录Auth0控制台,进入「应用程序 > 常规」页面,确保clientID完全复制正确,无多余空格或字符。
    • 确认「允许的回调URL」已添加baseURL + /callback,比如https://3803-188-124-153-232.ngrok.io/callback。
    • 确认「允许的注销URL」已添加你的baseURL,比如https://3803-188-124-153-232.ngrok.io。
  • 验证网络连通性:
    • 确保ngrok隧道处于活跃状态,直接访问你的ngrok URL能正常返回Express首页的"hello"。
    • 本地执行curl https://<你的租户名>.auth0.com/.well-known/openid-configuration,确认能返回正常的JSON配置,排除防火墙或代理拦截问题。
  • 更新依赖版本:执行npm update express-openid-connect,确保使用最新稳定版本的express-openid-connect,避免版本兼容问题。
  • 替换临时secret:代码中secret: 'secret'是临时值,生产环境需替换为32位以上的复杂随机字符串,当前报错虽与此无关,但需注意后续安全性。

内容的提问来源于stack exchange,提问作者Elias Knudsen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 09:31:05