ABP v4.4集成IdentityServer后带Token请求出现CORS认证错误问题
ABP 4.4集成IdentityServer获取Token后请求application-configuration返回CORS错误问题解决方案
运行环境
- ABP 4.4版本应用,集成IdentityServer、Angular前端、EF Core
问题现象
- Angular客户端向同域名的IdentityServer(API与IdentityServer共用同一URL)发送用户名密码请求,成功获取Token后,紧接着发起的
api/abp/application-configuration请求返回CORS错误 - 相同应用使用本地配置在QA本地环境可正常运行
- 应用启动阶段未携带Token的
api/abp/application-configuration请求也能正常调用
已排查内容
- 已确认应用配置中的CorsOrigins与IdentityServerClientCorsOrigins完全匹配,无空格问题
- 前后端均使用HTTPS协议,仅端口不同,可通过日志验证,存在日志返回内容未携带协议的异常情况(仅显示domain:1000)
问题定位
注释app.UseAuthentication();、app.UseJwtTokenMiddleware();两行代码,并移除类的Authorize特性后,应用运行正常无CORS错误,可确认该问题为认证相关问题。
错误日志
2021-09-04 10:42:24.731 -04:00 [INF] Request starting HTTP/2 OPTIONS https://domain:1000/.well-known/openid-configuration - - 2021-09-04 10:42:24.745 -04:00 [INF] CORS policy execution successful. 2021-09-04 10:42:24.751 -04:00 [INF] Request finished HTTP/2 OPTIONS https://domain:1000/.well-known/openid-configuration - - - 204 - - 19.7919ms 2021-09-04 10:42:24.793 -04:00 [INF] Request starting HTTP/2 GET https://domain:1000/.well-known/openid-configuration - - 2021-09-04 10:42:24.794 -04:00 [INF] CORS policy execution successful. 2021-09-04 10:42:46.050 -04:00 [ERR] Exception occurred while processing message. System.InvalidOperationException: IDX20803: Unable to obtain configuration from: 'System.String'. System.IO.IOException: IDX20804: Unable to retrieve document from: 'System.String'. System.Net.Http.HttpRequestException: A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond. (domain:1000) System.Net.Sockets.SocketException (10060): A connection attempt failed because the connected party did not properly respond after a period of time, or established connection failed because connected host has failed to respond.
根因分析
日志中的IDX20803错误说明JWT认证中间件在验证Token时,无法访问IdentityServer的OpenID配置端点。问题出在服务器端内部请求逻辑:当请求携带Token时,JWT中间件会主动请求/.well-known/openid-configuration获取公钥等配置信息,但服务器环境无法解析domain:1000或没有正确配置协议,导致内部请求超时失败,认证流程中断,最终返回CORS错误(本质是认证失败导致响应没有携带CORS头)。
解决方案
按优先级尝试以下操作:
- 显式配置带协议的JWT权威地址:在ABP模块的JWT配置位置,将Authority字段补全为完整的带HTTPS协议地址,例如
https://domain:1000,不要仅填写域名加端口,避免中间件默认补全协议出错。 - 配置服务器本地hosts映射:如果服务器内部无法解析
domain:1000,在服务器的hosts文件中添加127.0.0.1 domain映射,让内部请求直接走本地回环地址,规避网络路由问题。 - 调整中间件加载顺序:确保
app.UseCors()的调用位置在app.UseAuthentication()和app.UseAuthorization()之前,保证OPTIONS请求在进入认证流程前就能拿到CORS头正常返回。 - 临时关闭元数据验证(仅用于问题排查,不建议生产使用):如果需要快速验证问题根因,可以在JWT配置中添加
RequireHttpsMetadata = false、ValidateIssuer = false跳过元数据请求验证,确认问题解决后再回退配置排查网络问题。
内容的提问来源于stack exchange,提问作者mnaveedtkxel
相关产品推荐
相关产品推荐

