ASP.NET Core Blazor WASM Docker部署后OIDC端点HTTP问题求助
Looks like your IdentityServer4 instance is mistakenly generating HTTP URLs for its metadata endpoint after deploying to Docker—this is a common issue when your app sits behind a reverse proxy (which Docker deployments often use, like Nginx or Docker's built-in proxy). The proxy handles HTTPS termination and forwards requests to your app over HTTP, so IdentityServer defaults to using that HTTP protocol for its endpoints. Here's how to fix it:
1. Fix the ForwardedHeaders Middleware Order
Your current Startup.Configure method has the UseForwardedHeaders call after UseIdentityServer—this is backwards. The forwarded headers need to be processed early in the pipeline so all subsequent middleware (including IdentityServer) can see the original HTTPS request details.
Update your Configure method to move UseForwardedHeaders to the top:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { app.UseResponseCompression(); // Move this to the START of the pipeline app.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto }); if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); app.UseDatabaseErrorPage(); app.UseWebAssemblyDebugging(); } else { app.UseExceptionHandler("/Error"); app.UseHsts(); } app.UseHttpsRedirection(); app.UseBlazorFrameworkFiles(); app.UseStaticFiles(); app.UseRouting(); app.UseIdentityServer(); app.UseAuthentication(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapRazorPages(); endpoints.MapControllers(); endpoints.MapHub<PlaylistHub>("/playlisthub"); endpoints.MapFallbackToFile("index.html"); }); UpdateDatabase(app); }
2. Explicitly Set IdentityServer's Public Origin (If Needed)
If adjusting the middleware order doesn't resolve the issue, you can force IdentityServer to use your HTTPS domain for all metadata endpoints by setting its PublicOrigin:
In ConfigureServices, modify your IdentityServer registration:
services.AddIdentityServer() .AddApiAuthorization<ApplicationUser, ApplicationDbContext>(options => { // Replace with your actual HTTPS domain options.IdentityServerOptions.PublicOrigin = "https://musicfusion.app"; });
For a more flexible setup (e.g., using environment variables), you can pull this value from your configuration:
- Add this to your
appsettings.json(or environment variables):
"IdentityServer": { "PublicOrigin": "https://musicfusion.app" }
- Then update
ConfigureServices:
services.AddIdentityServer() .AddApiAuthorization<ApplicationUser, ApplicationDbContext>(); // Apply PublicOrigin from config if set var publicOrigin = Configuration["IdentityServer:PublicOrigin"]; if (!string.IsNullOrEmpty(publicOrigin)) { services.Configure<IdentityServerOptions>(options => { options.PublicOrigin = publicOrigin; }); }
3. Verify Reverse Proxy Configuration
Make sure your reverse proxy (Nginx, Traefik, etc.) is sending the required forwarded headers to your app. For example, in Nginx you'd add these lines to your location block:
proxy_set_header X-Forwarded-For $remote_addr; proxy_set_header X-Forwarded-Proto $scheme;
This ensures your ASP.NET Core app knows the original request was over HTTPS.
How to Test
After deploying these changes, visit https://musicfusion.app/.well-known/openid-configuration directly. Check the JSON response—all endpoints (like issuer, authorization_endpoint, etc.) should use https:// instead of http://.
内容的提问来源于stack exchange,提问作者Mikerad

