You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用IdentityServer4的/connect/authorize端点无法获取Authorization Code

问题原因及修复方案

行为说明

你观察到的调用/connect/authorize仅返回重定向URL是正常逻辑:IdentityServer4会先校验请求用户是否已登录,未登录时会直接重定向到你配置的登录页(https://localhost:6001/login),只有用户完成登录后才会携带Authorization Code重定向到你配置的回调地址。你在Postman中直接调用接口时没有携带有效的身份认证Cookie,因此只会触发重定向到登录页的逻辑,无法直接拿到Code。

配置错误点排查

  1. 回调路径拼写错误
    你的OpenIdConnect配置中回调路径写错:
// 错误写法,少了字母i
options.CallbackPath = "/signin-odic";
// 修正为
options.CallbackPath = "/signin-oidc";

这个错误会导致就算登录成功,你也无法接收到IdentityServer返回的授权码。

  1. 客户端允许的Scope不匹配
    你的OpenIdConnect配置中请求了profile、email两个Scope,但客户端配置的AllowedScopes中没有添加这两个值,同时你写的fullcontroll大概率是拼写错误,建议修正为正确的Scope名。
    修正后的客户端AllowedScopes配置参考:
AllowedScopes = {"WebAPI","fullcontrol",IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, IdentityServerConstants.StandardScopes.Email},
  1. 回调地址配置不匹配
    你客户端配置的RedirectUris是https://localhost:6001/login,但OpenIdConnect的回调路径对应的完整地址应该是https://<你的服务地址>/signin-oidc,两者不一致会导致IdentityServer拒绝返回授权码。请把实际用到的所有回调地址都添加到RedirectUris列表中。

  2. 冗余配置项
    你客户端配置了RequireClientSecret = false,也就是SPA应用不需要携带客户端密钥,但OpenIdConnect配置中还填写了ClientSecret = "secret",该配置属于冗余,可删除避免后续混淆。

验证方法

不要直接在Postman调用/connect/authorize接口,选择以下两种方式验证:

  • 从浏览器端触发认证跳转,完成登录流程后会自动携带授权码跳转到回调地址
  • 使用Postman的「Authorization」标签下的OAuth2.0功能,配置好对应参数后点击「Get New Access Token」,会自动走完完整的授权流程,就能拿到Authorization Code。

内容的提问来源于stack exchange,提问作者Strif3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.04 20:09:02