You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Boilerplate Core2.0 Angular项目IdentityServer双认证失效求助

求助:ABP Core 2.0 Angular项目中同时兼容IdentityServer与自定义JWT认证的问题

大家好,我最近基于ASP.NET Boilerplate创建了Core 2.0 Angular项目,按照官方的IdentityServer文档实现后,示例一直跑不起来,核心问题是没办法同时支持Angular客户端(用自定义接口生成的JWT)和API客户端(通过IdentityServer获取的令牌)的认证,其中一个明显的问题出在AuthConfigurer.cs,API客户端拿到的令牌始终过不了验证。

目前的配置和代码情况

1. 自定义的令牌生成逻辑(TokenAuthController)

我在TokenAuthController里写了自己的令牌生成方法:

private string CreateAccessToken(IEnumerable<Claim> claims, TimeSpan? expiration = null) {
    var now = DateTime.UtcNow;
    var jwtSecurityToken = new JwtSecurityToken(
        issuer: _configuration.Issuer,
        audience: _configuration.Audience,
        claims: claims,
        notBefore: now,
        expires: now.Add(expiration ?? _configuration.Expiration),
        signingCredentials: _configuration.SigningCredentials
    );
    return new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken);
}

2. Startup里的IdentityServer与认证配置

Startup中同时注册了IdentityServer和Authentication服务,但两边的令牌验证规则看起来不统一:

services.AddIdentityServer()
    .AddDeveloperSigningCredential()
    .AddInMemoryIdentityResources(IdentityServerConfig.GetIdentityResources())
    .AddInMemoryApiResources(IdentityServerConfig.GetApiResources())
    .AddInMemoryClients(IdentityServerConfig.GetClients())
    .AddAbpPersistedGrants<IAbpPersistedGrantDbContext>()
    .AddAbpIdentityServer<User>();

services.AddAuthentication().AddIdentityServerAuthentication("IdentityBearer", options => {
    options.Authority = "http://localhost:62114/";
    options.RequireHttpsMetadata = false;
});

3. 两种客户端的令牌获取方式

  • Angular客户端:直接调用上面的CreateAccessToken接口生成JWT令牌
  • API客户端:通过IdentityServer的令牌端点获取,代码如下:
var disco = await DiscoveryClient.GetAsync("http://localhost:21021");
var httpHandler = new HttpClientHandler();
httpHandler.CookieContainer.Add(new Uri("http://localhost:21021/"), new Cookie(MultiTenancyConsts.TenantIdResolveKey, "1")); // 设置租户ID
var tokenClient = new TokenClient(disco.TokenEndpoint, "AngularSPA", "secret", httpHandler);
var tokenResponse = await tokenClient.RequestResourceOwnerPasswordAsync("admin", "123qwe", "default-api"); // 也试过RequestClientCredentialsAsync

当前遇到的困境

现在的情况是两种令牌只能有一个能通过认证,要么Angular的能用,要么API客户端的能用,没办法同时支持。我之前参考过双认证的相关方案,但还是没解决问题,想请各位大佬给点建议,看看哪里配置错了或者有没有其他可行的方案。

内容的提问来源于stack exchange,提问作者Tuğrul Karakaya

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:45:34