Identity Server 4 Docker部署登录跳转失败问题求助
我是IdentityServer4新手,搭建了包含三个项目的测试方案:1.IdentityServer4、2.API资源服务、3.Razor客户端。本地运行一切正常,但部署到Docker后出现登录跳转异常。
问题现象
启动Web客户端后无法正常跳转到IdentityServer4登录页,排查后怀疑是证书或网络DNS问题,尝试两种配置均未解决:
配置1:将Authority地址设为
http://identityserver4:9001
客户端抛出连接拒绝错误,无法获取OpenID配置文档,即使IdentityServer4服务关闭也报相同错误,测试HTTP请求同样无法连通。错误信息如下:SocketException: Connection refused
System.Net.Sockets.Socket+AwaitableSocketAsyncEventArgs.ThrowException(SocketError error, CancellationToken cancellationToken)HttpRequestException: Connection refused (identityserver4:9001)
System.Net.Http.HttpConnectionPool.ConnectToTcpHostAsync(string host, int port, HttpRequestMessage initialRequest, bool async, CancellationToken cancellationToken)IOException: IDX20804: Unable to retrieve document from: 'http://identityserver4:9001/.well-known/openid-configuration'.
Microsoft.IdentityModel.Protocols.HttpDocumentRetriever.GetDocumentAsync(string address, CancellationToken cancel)InvalidOperationException: IDX20803: Unable to obtain configuration from: 'http://identityserver4:9001/.well-known/openid-configuration'.
Microsoft.IdentityModel.Protocols.ConfigurationManager.GetConfigurationAsync(CancellationToken cancel)配置2:将Authority地址设为
http://identityserver4:80
客户端成功跳转,但浏览器提示dial tcp: lookup identityserver4 on 127.0.0.11:53: no such host,不过客户端内部HTTP请求能正常获取配置文档。
相关配置信息
docker-compose.override.yml
version: '3.4' services: identityserver4: container_name: identityserver4 environment: - ASPNETCORE_ENVIRONMENT=Development ports: - "9001:80" networks: - mynet clientapp: container_name: clientapp environment: - ASPNETCORE_ENVIRONMENT=Development ports: - "5001:80" depends_on: - identityserver4 networks: - mynet apiresource: container_name: apiresource environment: - ASPNETCORE_ENVIRONMENT=Development ports: - "8001:80" networks: - mynet networks: mynet: external: true
Identity Server客户端配置(Config.cs)
new Client { ClientId = "razorClient", ClientName = "RAZOR Client App", AllowedGrantTypes= GrantTypes.Hybrid, RequirePkce = false, AllowRememberConsent = false, RedirectUris = new List<string>() { "http://clientapp:80/signin-oidc" }, PostLogoutRedirectUris = new List<string>() { "http://clientapp:80/signout-callback-oidc" }, ClientSecrets = new List<Secret> { new Secret("secret".Sha256()) }, AllowedScopes = new List<string>() { IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, "MYAPI" }, AllowAccessTokensViaBrowser = true, }
Identity Server Program.cs
using IdentityServer; var builder = WebApplication.CreateBuilder(args); Microsoft.IdentityModel.Logging.IdentityModelEventSource.ShowPII = true; builder.Services.AddControllersWithViews(); builder.Services.AddIdentityServer(options => { options.IssuerUri = "http://identityserver4:80"; }) .AddInMemoryClients(Config.Clients) .AddInMemoryIdentityResources(Config.IdentityResources) //.AddInMemoryApiResources(Config.ApiResources) .AddInMemoryApiScopes(Config.ApiScopes) .AddTestUsers(Config.TestUsers) .AddDeveloperSigningCredential(); var app = builder.Build(); if (!app.Environment.IsDevelopment()) { app.UseHttpsRedirection(); } app.UseStaticFiles(); app.UseRouting(); app.UseIdentityServer(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapDefaultControllerRoute(); }); app.Run();
客户端Program.cs
using ClientApp.Data; using Microsoft.AspNetCore.Authentication.Cookies; using Microsoft.AspNetCore.Authentication.OpenIdConnect; using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Components; using Microsoft.AspNetCore.Components.Web; using Microsoft.AspNetCore.Mvc.Authorization; var builder = WebApplication.CreateBuilder(args); Microsoft.IdentityModel.Logging.IdentityModelEventSource.ShowPII = true; builder.Services.AddHttpClient(); // Add services to the container. builder.Services.AddRazorPages(); builder.Services.AddServerSideBlazor(); builder.Services.AddSingleton<WeatherForecastService>(); builder.Services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme; }) .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme) .AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options => { options.Authority = "http://identityserver4:80"; options.MetadataAddress = "http://identityserver4:80/.well-known/openid-configuration"; //options.BackchannelHttpHandler = new HttpClientHandler //{ // ServerCertificateCustomValidationCallback = (message, cert, chain, errors) => true //}; options.RequireHttpsMetadata = false; options.ClientId = "razorClient"; options.ClientSecret = "secret"; options.ResponseType = "code id_token"; options.Scope.Add("openid"); options.Scope.Add("profile"); options.Scope.Add("MYAPI"); options.SaveTokens = true; options.GetClaimsFromUserInfoEndpoint = true; }); builder.Services.AddMvcCore(options => { var policy = new AuthorizationPolicyBuilder() .RequireAuthenticatedUser() .Build(); options.Filters.Add(new AuthorizeFilter(policy)); }); var app = builder.Build(); // Configure the HTTP request pipeline. if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Error"); app.UseHttpsRedirection(); // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts. app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.MapBlazorHub(); app.MapFallbackToPage("/_Host"); app.Run();
内容的提问来源于stack exchange,提问作者Rouzbeh Zarandi

