如何在Duende/Identity Server中从数据库读取客户端及其他配置?
Duende IdentityServer:移除内存配置,从数据库读取配置
问题描述
此前使用Config.cs存储客户端、身份资源及API范围等配置,现已将配置迁移至IdentityServer数据库。希望移除Config.cs并直接从数据库读取配置,已在Program.cs中配置了数据库存储,但不清楚如何替换原先的内存配置方法:
builder.Services.AddIdentityServer() .AddConfigurationStore(options => { options.ConfigureDbContext = b => b.UseSqlServer(connectionString, sql => sql.MigrationsAssembly(migrationsAssembly)); }) .AddOperationalStore(options => { options.ConfigureDbContext = b => b.UseSqlServer(connectionString, sql => sql.MigrationsAssembly(migrationsAssembly)); }) //.AddInMemoryIdentityResources(Config.IdentityResources) //.AddInMemoryApiScopes(Config.ApiScopes) //.AddInMemoryClients(Config.Clients) .AddMyUserStore();
解决方案
你不需要替换那三行注释掉的代码——直接保留注释状态即可,原因如下:
当你调用AddConfigurationStore时,已经告诉IdentityServer从指定的数据库中读取配置数据(客户端、身份资源、API范围等),替代了原先的内存存储方式。后续IdentityServer会自动从ConfigurationDbContext对应的数据库表中加载这些配置。
不过需要完成以下两步确保数据库配置生效:
执行数据库迁移生成配置表
使用EF Core迁移命令生成IdentityServer所需的配置表:- 若使用Package Manager Console:
Add-Migration InitialIdentityServerConfigurationDb -Context ConfigurationDbContext Update-Database -Context ConfigurationDbContext - 若使用.NET CLI:
dotnet ef migrations add InitialIdentityServerConfigurationDb -c ConfigurationDbContext -o Migrations/IdentityServer/ConfigurationDb dotnet ef database update -c ConfigurationDbContext
- 若使用Package Manager Console:
初始化数据库配置数据(可选)
如果数据库中还没有之前在Config.cs里的配置数据,可以一次性导入:
在Program.cs的app.Build()之后,添加初始化逻辑(仅首次运行时执行):var app = builder.Build(); // 初始化配置数据 using (var scope = app.Services.CreateScope()) { var configContext = scope.ServiceProvider.GetRequiredService<ConfigurationDbContext>(); // 导入身份资源 if (!configContext.IdentityResources.Any()) { foreach (var resource in Config.IdentityResources) { configContext.IdentityResources.Add(resource.ToEntity()); } configContext.SaveChanges(); } // 导入API范围 if (!configContext.ApiScopes.Any()) { foreach (var apiScope in Config.ApiScopes) { configContext.ApiScopes.Add(apiScope.ToEntity()); } configContext.SaveChanges(); } // 导入客户端 if (!configContext.Clients.Any()) { foreach (var client in Config.Clients) { configContext.Clients.Add(client.ToEntity()); } configContext.SaveChanges(); } } // 后续中间件配置... app.UseIdentityServer(); // ...数据导入完成后,你就可以安全删除
Config.cs文件了。后续配置维护
之后如需修改客户端、资源等配置,直接操作数据库对应的表(如Clients、IdentityResources、ApiScopes)即可,也可以部署IdentityServer的管理UI来可视化维护。
内容的提问来源于stack exchange,提问作者golrokh ka
相关产品推荐
相关产品推荐

