You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core中JWT Token校验参数Clock Skew配置不生效问题

问题原因

AddIdentityServerJwt 会注册名为 IdentityServerJwtBearer 的专属JWT验证方案,你当前无参数的 Configure<JwtBearerOptions>、未指定方案的 IPostConfigureOptions 配置都只会作用于默认JWT验证方案,不会生效到IdentityServer专属的验证方案上,因此配置会被忽略,始终保留默认5分钟的ClockSkew。

修复方案

你可以任选以下一种方式配置:

  • 方式1:配置时明确指定IdentityServer的JWT验证方案名
// 直接指定方案名配置参数
services.Configure<JwtBearerOptions>("IdentityServerJwtBearer", options =>
{
    options.TokenValidationParameters.ClockSkew = TimeSpan.FromSeconds(9875664);
});

// PostConfigure也要对应指定方案名才会生效
services.TryAddEnumerable(ServiceDescriptor
   .Singleton<IPostConfigureOptions<JwtBearerOptions>>(new ConfigureJwtBearerOptions("IdentityServerJwtBearer")));
  • 方式2:在AddIdentityServerJwt链式调用中直接配置,无需手动指定方案名
services.AddAuthentication()
        .AddIdentityServerJwt(options =>
        {
            options.TokenValidationParameters.ClockSkew = TimeSpan.FromSeconds(9875664);
        });
  • 方式3:将IdentityServer的JWT方案设为全局默认验证方案,原有全局无指定方案的配置就会自动生效
services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = "IdentityServerJwtBearer";
    options.DefaultChallengeScheme = "IdentityServerJwtBearer";
})
.AddIdentityServerJwt();

内容的提问来源于stack exchange,提问作者Gimmly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 18:06:03