You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Identity Server4部署到Azure生产环境报invalid_grant错误求助

核心根因分析

你遇到的授权报错由以下几个配置冲突/不匹配问题共同导致:

  • 配置源优先级冲突:你在IdentityServer配置中同时注册了AddInMemoryClients(读取Config.cs的内存配置)和AddConfigurationStore(读取数据库客户端配置),IdentityServer默认优先读取数据库配置,本地测试时可能未正常初始化配置库使用了内存配置所以运行正常,部署到Azure后读取数据库的旧配置,你修改的Config.cs规则完全不生效。
  • RedirectUri不匹配:桌面客户端传入的重定向地址为http://127.0.0.1:53508,但你Config.cs中配置的合法重定向地址为http://127.0.0.1:53508/callback,后缀不匹配,就算用内存配置也会校验失败。
  • 数据库客户端配置缺失:你提供的Clients表记录未明确开启PKCE支持,IdentityServer4 4.x+版本对授权码流默认强制要求PKCE校验,你客户端已经传递了code_challenge参数,但数据库中的客户端配置未开启对应权限,会被判定为不合法的授权类型请求。

修复步骤

  1. 清理重复配置源
    如果要使用数据库管理客户端配置,移除AddInMemoryIdentityResources、AddInMemoryApiResources、AddInMemoryClients三个内存配置注册代码,避免优先级冲突;如果要使用内存配置,删除AddConfigurationStore注册逻辑。
// 示例:仅保留数据库配置源的代码
var builder = services.AddIdentityServer(options =>
    {
        options.Authentication.CookieLifetime = TimeSpan.FromMinutes(5);
        options.Authentication.CookieSlidingExpansion = false;
        options.Events.RaiseErrorEvents = true;
        options.Events.RaiseInformationEvents = true;
        options.Events.RaiseFailureEvents = true;
        options.Events.RaiseSuccessEvents = true;
        options.IssuerUri = Configuration["AuthServerUrl"];
    })
    // 移除以下三行内存配置
    //.AddInMemoryIdentityResources(Config.GetIdentityResources())
    //.AddInMemoryApiResources(Config.GetApiResources())
    //.AddInMemoryClients(Config.GetClients())
    .AddConfigurationStore(options =>
    {
        options.ConfigureDbContext = b => b.UseSqlServer(
            Configuration.GetConnectionString("AuthDB"),
            sql => sql.MigrationsAssembly(migrationsAssembly));
    })
    .AddOperationalStore(options =>
    {
        options.ConfigureDbContext = b => b.UseSqlServer(
            Configuration.GetConnectionString("AuthDB"),
            sql => sql.MigrationsAssembly(migrationsAssembly));
    });
  1. 统一RedirectUri配置
    要么修改客户端重定向地址为带后缀的http://127.0.0.1:53508/callback,要么在合法重定向地址列表中添加http://127.0.0.1:53508。
// 示例:Config.cs新增无后缀的重定向地址
RedirectUris =
{
    "http://127.0.0.1:53508/callback",
    "http://127.0.0.1:53508"
},
  1. 修正数据库客户端配置
    在Clients表中为desktopClient新增RequirePkce = 1的配置,同时确认ClientGrantTypes表中authorization_code授权类型已正确绑定到对应客户端ID。如果是EF迁移生成的配置,直接在Config.cs的Client定义中添加配置后重新同步到数据库即可:
new Client
{
    ClientId = "desktopClient",
    ClientName = "Desktop",
    AllowedGrantTypes = GrantTypes.Code,
    RequirePkce = true, // 新增:开启PKCE支持,匹配客户端传参
    RequireClientSecret = false, // 桌面端属于公开客户端,不需要校验客户端密钥可以关闭
    ClientSecrets = {new Secret("secret".Sha256())},
    AllowAccessTokensViaBrowser = true,
    AccessTokenLifetime = 60 * 30,
    AllowedScopes = {"openid profile api offline_access"},
    AllowedCorsOrigins =
    {
        "https://mysite.azurewebsites.net",
        "https://localhost:44323"
    },
    RedirectUris =
    {
        "http://127.0.0.1:53508/callback",
        "http://127.0.0.1:53508"
    },
    PostLogoutRedirectUris =
    {
        "http://127.0.0.1:53508/login"
    },
    RequireConsent = false
}
  1. 验证部署配置
    部署到Azure后,访问IdentityServer的发现端点{你的AuthServer地址}/.well-known/openid-configuration,确认返回的配置和你预期一致,没有配置缓存问题。

内容的提问来源于stack exchange,提问作者Fraser Booth

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.03 16:18:01