You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor WASM中Duende.IdentityServer自定义Scope遇invalid_scope等问题

解决Client Credentials流自定义Scope配置问题

核心配置逻辑梳理

要解决你的问题,需明确IdentityServer的几个关键规则:

  • 自定义Scope必须先在ApiScopes中注册,才能被客户端引用
  • Client Credentials类型的客户端需单独配置AllowedScopes,且Scope必须属于ApiScopes范畴(而非IdentityResources)
  • 不要混合默认客户端配置与自定义InMemoryClients,否则易因客户端ID/密钥不匹配触发invalid_client错误

正确配置步骤(Server端项目)

1. 注册自定义ApiScope

在Server项目的Program.cs中,找到IdentityServer配置段,直接向现有配置添加自定义Scope:

builder.Services.AddIdentityServer()
    .AddApiAuthorization<ApplicationUser, ApplicationDbContext>(options =>
    {
        // 注册专属的IntegrationAPI Scope
        options.ApiScopes.Add(new ApiScope("WebApplication4.IntegrationAPI", "Integration API专属访问权限"));
    })
    .AddDeveloperSigningCredential();

注意:不要替换默认的AddApiAuthorization集成逻辑,直接追加Scope即可,避免与默认的EF存储冲突。

2. 配置Client Credentials专属客户端

同样在IdentityServer配置中,新增Client Credentials类型的客户端,仅分配自定义Scope:

builder.Services.AddIdentityServer()
    .AddApiAuthorization<ApplicationUser, ApplicationDbContext>(options =>
    {
        options.ApiScopes.Add(new ApiScope("WebApplication4.IntegrationAPI", "Integration API专属访问权限"));
        
        // 添加Client Credentials客户端
        options.Clients.Add(new Client
        {
            ClientId = "IntegrationApiServiceClient",
            ClientName = "集成API服务客户端",
            AllowedGrantTypes = GrantTypes.ClientCredentials,
            ClientSecrets = { new Secret("your-secure-client-secret-here".Sha256()) },
            // 仅赋予该客户端自定义Scope权限
            AllowedScopes = { "WebApplication4.IntegrationAPI" },
            AccessTokenLifetime = 3600 // 可选:设置Token有效期
        });
    })
    .AddDeveloperSigningCredential();

不要覆盖默认的Blazor WASM前端客户端配置,仅新增专属客户端,避免原有前端授权流程失效。

3. 配置专属授权策略

在Program.cs中添加授权策略,用于保护需要该Scope的API端点:

builder.Services.AddAuthorization(options =>
{
    options.AddPolicy("IntegrationApiOnly", policy =>
    {
        policy.RequireAuthenticatedUser();
        policy.RequireClaim("scope", "WebApplication4.IntegrationAPI");
    });
});

在目标API控制器上应用该策略:

[Authorize(Policy = "IntegrationApiOnly")]
[ApiController]
[Route("api/integration")]
public class IntegrationApiController : ControllerBase
{
    // 你的API业务方法
}

常见错误排查

  • invalid_scope:
    • 检查自定义Scope名称是否与注册、请求时的参数完全一致(大小写敏感)
    • 确认客户端的AllowedScopes已包含该Scope
    • 访问https://你的服务器地址/.well-known/openid-configuration,查看scopes_supported中是否存在该Scope
  • invalid_client:
    • 校验请求Token时的client_id和client_secret是否与配置完全匹配
    • 不要用AddInMemoryClients替换默认客户端存储,直接在options.Clients中新增客户端即可

内容的提问来源于stack exchange,提问作者Ogglas

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 12:50:25