You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用endsession API无法登出Identity Service问题求助

问题根因&解决方案

1. 自定义Logout接口除logoutId外其余参数全为null是正常现象

IdentityServer的EndSession端点中间件会先处理你传入的id_token_hint、post_logout_redirect_uri、session等参数,校验通过后生成唯一logoutId,再302重定向到你配置的LogoutPath对应接口,重定向时仅携带logoutId参数,不会透传原始请求的其他参数,你用[FromQuery]接收其余参数自然全为null,不属于配置错误。

2. LogoutRequest除客户端信息外其余属性全空的排查步骤

  • 首先校验客户端配置的PostLogoutRedirectUris集合,需和你请求传入的post_logout_redirect_uri完全匹配,大小写、末尾斜杠差异都会导致校验失败,参数无法注入到LogoutRequest中
  • 确认你生成ID Token时已经包含sid(会话ID)声明,该声明默认包含在openid标准身份资源中,若你自定义了身份资源,需显式把sid加入到ID Token的返回声明列表,EndSession端点依赖该声明做会话匹配
  • 若你使用的是Duende IdentityServer v6及以上版本,需在服务注册时显式配置允许EndSession参数透传:
builder.Services.AddIdentityServer(opt =>
{
    opt.Endpoints.EnableEndSessionEndpoint = true;
    // 允许EndSession参数写入LogoutContext
    opt.Authentication.SaveSignoutContext = true;
})
.AddInMemoryIdentityResources(new List<IdentityResource>
{
    new IdentityResources.OpenId(),
    new IdentityResources.Profile()
});
  • 不要直接把登出参数传到你的自定义/logout接口,必须先请求官方/connect/endsession端点,让中间件完成参数校验和上下文写入,再跳转到自定义登出逻辑。

3. 登出不生效的修复方法

你当前的代码缺少了清空认证凭证的核心步骤,补充后完整逻辑参考:

[HttpGet("logout")]
public async Task<IActionResult> LogOut([FromQuery] string logoutId)
{ 
    LogoutRequest context = await InteractionService.GetLogoutContextAsync(logoutId);
    // 清空IdentityServer认证Cookie
    await HttpContext.SignOutAsync(IdentityServerConstants.DefaultCookieAuthenticationScheme);
    // 若你集成了ASP.NET Core Identity,还需要清空Identity的Cookie
    await HttpContext.SignOutAsync(IdentityConstants.ApplicationScheme);
    
    // 合法重定向跳转
    if (context?.PostLogoutRedirectUri != null)
    {
        return Redirect(context.PostLogoutRedirectUri);
    }
    return Redirect("~/");
}

内容的提问来源于stack exchange,提问作者Konrad Viltersten

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.06 21:42:02