在Asp.Net Core 2.1中用Identity Server 3验证Bearer令牌遇500错误求助
我之前也踩过类似的坑,Asp.Net Core的IdentityServerAuthentication中间件对IdentityServer3的兼容性需要一些细节调整。你遇到的You must either set Authority or IntrospectionEndpoint错误,本质是中间件没能成功从你的IdentityServer3实例获取到必要的元数据——哪怕你已经配置了Authority,只要元数据请求失败,中间件就会判定Authority无效。
下面是几个针对性的解决方案,按优先级尝试:
1. 先修正Authority的地址格式
这是最容易忽略的问题:你的Authority末尾加了斜杠,中间件在拼接OpenID发现文档路径时会生成重复斜杠(比如https://demo.identity.abc.com/identity//.well-known/openid-configuration),导致请求元数据失败,进而触发错误。
把Authority改成不带末尾斜杠的形式:
options.Authority = "https://demo.identity.abc.com/identity"; // 移除末尾的/
同时手动访问https://demo.identity.abc.com/identity/.well-known/openid-configuration,确认能返回正常的JSON(包含issuer、jwks_uri等核心字段)。
2. 切换到JwtBearer认证中间件(更适配IS3隐式流)
IdentityServerAuthentication中间件是为IdentityServer4优化的,对于IS3的隐式流(返回JWT令牌),直接使用JwtBearer中间件往往更稳定。替换你的认证配置为:
using Microsoft.AspNetCore.Authentication.JwtBearer; using Microsoft.IdentityModel.Tokens; using Microsoft.IdentityModel.Protocols.OpenIdConnect; using Microsoft.IdentityModel.Protocols; // ... services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) .AddJwtBearer(options => { options.Authority = "https://demo.identity.abc.com/identity"; options.TokenValidationParameters = new TokenValidationParameters { ValidateAudience = true, ValidAudience = "Test_Api", // 你的API Scope ValidateIssuer = true, ValidIssuer = "https://demo.identity.abc.com/identity", // IS3的Issuer地址 ValidateIssuerSigningKey = true, // 如果自动从元数据获取签名密钥失败,手动添加IS3使用的证书 // IssuerSigningKeys = new List<SecurityKey> { new X509SecurityKey(new X509Certificate2("path/to/your-is3-cert.pfx", "cert-password")) } }; // 显式配置配置管理器,确保正确解析IS3的发现文档 options.ConfigurationManager = new ConfigurationManager<OpenIdConnectConfiguration>( $"{options.Authority}/.well-known/openid-configuration", new OpenIdConnectConfigurationRetriever(), new HttpDocumentRetriever()); });
保留你原来的ScopePolicy和其他Mvc配置——因为IS3的隐式流令牌通常不会把API名称作为audience,所以需要通过ScopePolicy来验证权限。
3. 确认中间件顺序
你当前的Configure方法里中间件顺序是对的:UseCors → UseAuthentication → UseMvc,这个顺序不能乱,UseAuthentication必须在UseMvc之前,否则认证逻辑不会生效。
尝试完上面的方案后,重新启动API测试,应该能解决这个500错误。
内容的提问来源于stack exchange,提问作者Ghanshyam Shukla

