You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Duende/Identity Server中从数据库读取客户端及其他配置?

Duende IdentityServer:移除内存配置,从数据库读取配置

问题描述

此前使用Config.cs存储客户端、身份资源及API范围等配置,现已将配置迁移至IdentityServer数据库。希望移除Config.cs并直接从数据库读取配置,已在Program.cs中配置了数据库存储,但不清楚如何替换原先的内存配置方法:

builder.Services.AddIdentityServer()
 .AddConfigurationStore(options =>
 {
    options.ConfigureDbContext = b => b.UseSqlServer(connectionString,
        sql => sql.MigrationsAssembly(migrationsAssembly));
})
.AddOperationalStore(options =>
{
    options.ConfigureDbContext = b => b.UseSqlServer(connectionString,
        sql => sql.MigrationsAssembly(migrationsAssembly));
})
//.AddInMemoryIdentityResources(Config.IdentityResources)
//.AddInMemoryApiScopes(Config.ApiScopes)
//.AddInMemoryClients(Config.Clients)
.AddMyUserStore();

解决方案

你不需要替换那三行注释掉的代码——直接保留注释状态即可,原因如下:

当你调用AddConfigurationStore时,已经告诉IdentityServer从指定的数据库中读取配置数据(客户端、身份资源、API范围等),替代了原先的内存存储方式。后续IdentityServer会自动从ConfigurationDbContext对应的数据库表中加载这些配置。

不过需要完成以下两步确保数据库配置生效:

  1. 执行数据库迁移生成配置表
    使用EF Core迁移命令生成IdentityServer所需的配置表:

    • 若使用Package Manager Console:
      Add-Migration InitialIdentityServerConfigurationDb -Context ConfigurationDbContext
      Update-Database -Context ConfigurationDbContext
      
    • 若使用.NET CLI:
      dotnet ef migrations add InitialIdentityServerConfigurationDb -c ConfigurationDbContext -o Migrations/IdentityServer/ConfigurationDb
      dotnet ef database update -c ConfigurationDbContext
      
  2. 初始化数据库配置数据(可选)
    如果数据库中还没有之前在Config.cs里的配置数据,可以一次性导入:
    在Program.cs的app.Build()之后,添加初始化逻辑(仅首次运行时执行):

    var app = builder.Build();
    
    // 初始化配置数据
    using (var scope = app.Services.CreateScope())
    {
        var configContext = scope.ServiceProvider.GetRequiredService<ConfigurationDbContext>();
        
        // 导入身份资源
        if (!configContext.IdentityResources.Any())
        {
            foreach (var resource in Config.IdentityResources)
            {
                configContext.IdentityResources.Add(resource.ToEntity());
            }
            configContext.SaveChanges();
        }
    
        // 导入API范围
        if (!configContext.ApiScopes.Any())
        {
            foreach (var apiScope in Config.ApiScopes)
            {
                configContext.ApiScopes.Add(apiScope.ToEntity());
            }
            configContext.SaveChanges();
        }
    
        // 导入客户端
        if (!configContext.Clients.Any())
        {
            foreach (var client in Config.Clients)
            {
                configContext.Clients.Add(client.ToEntity());
            }
            configContext.SaveChanges();
        }
    }
    
    // 后续中间件配置...
    app.UseIdentityServer();
    // ...
    

    数据导入完成后,你就可以安全删除Config.cs文件了。

  3. 后续配置维护
    之后如需修改客户端、资源等配置,直接操作数据库对应的表(如Clients、IdentityResources、ApiScopes)即可,也可以部署IdentityServer的管理UI来可视化维护。

内容的提问来源于stack exchange,提问作者golrokh ka

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 01:01:07