You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer4从3.1.4升级到4.0.0后Scope无效问题排查

Fixing Unrecognized ApiScope After IdentityServer4 3.1.4 → 4.0.0 Upgrade

Let's break down why your IdentityPortal.API scope isn't being recognized post-upgrade, and walk through the fixes step by step.

1. Critical Issue: Missing ApiScopes in GetAllResourcesAsync

The primary problem lies in your CustomResourceStore implementation. In IdentityServer4 4.x, the server's metadata (including the scopes_supported list) is built from the Resources object returned by GetAllResourcesAsync. Your current code omits the ApiScopes collection entirely:

public Task<Resources> GetAllResourcesAsync() {
    var result = new Resources(GetAllIdentityResources(), GetAllApiResources(), null);
    return Task.FromResult(result);
}

You're passing null for the third parameter (which expects an IEnumerable<ApiScope>). That's why your custom scope never appears in the metadata.

Fix: Update the method to include your stored ApiScopes:

public Task<Resources> GetAllResourcesAsync() {
    var result = new Resources(GetAllIdentityResources(), GetAllApiResources(), GetAllApiScopes());
    return Task.FromResult(result);
}

2. Ensure ApiScopes Exist in Your MongoDB Store

Since you're using a custom IResourceStore that pulls data from MongoDB, you need to confirm:

  • A valid ApiScope document for IdentityPortal.API exists in your database. It should match the definition in your Config.AllowedScopes() method:
    new ApiScope(apiScope) // apiScope = "IdentityPortal.API"
    
  • Your FindApiScopesByNameAsync method is correctly querying for these scopes (your current implementation looks correct, but verify the data exists in MongoDB).

⚠️ Note: The .AddInMemoryApiScopes(Config.AllowedScopes()) call in your IdentityServer setup is ignored when using a custom IResourceStore. IdentityServer prioritizes your custom store over in-memory configurations, so the scope must exist in MongoDB.

3. Verify ApiResource and ApiScope Alignment

In IdentityServer4 4.x, ApiResource and ApiScope are decoupled. Double-check that:

  • The Scopes property on your ApiResource exactly matches the Name of your ApiScope:
    new ApiResource(apiScope, "Falcon Api") {
        Scopes = new List<string>{apiScope}, // Matches "IdentityPortal.API"
        // ... claims
    }
    
  • Your ApiScope is configured with the correct name in both code and MongoDB.

Final Validation Steps

After applying these fixes:

  1. Restart your IdentityServer instance.
  2. Visit the metadata endpoint at https://localhost:5001/.well-known/openid-configuration and confirm IdentityPortal.API appears in the scopes_supported array.
  3. Retest your React application's authentication request—IdentityServer should now correctly recognize the IdentityPortal.API scope.

内容的提问来源于stack exchange,提问作者San Jaisy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.08 10:12:35