ASP.NET Boilerplate Core2.0 Angular项目IdentityServer双认证失效求助
求助:ABP Core 2.0 Angular项目中同时兼容IdentityServer与自定义JWT认证的问题
大家好,我最近基于ASP.NET Boilerplate创建了Core 2.0 Angular项目,按照官方的IdentityServer文档实现后,示例一直跑不起来,核心问题是没办法同时支持Angular客户端(用自定义接口生成的JWT)和API客户端(通过IdentityServer获取的令牌)的认证,其中一个明显的问题出在AuthConfigurer.cs,API客户端拿到的令牌始终过不了验证。
目前的配置和代码情况
1. 自定义的令牌生成逻辑(TokenAuthController)
我在TokenAuthController里写了自己的令牌生成方法:
private string CreateAccessToken(IEnumerable<Claim> claims, TimeSpan? expiration = null) { var now = DateTime.UtcNow; var jwtSecurityToken = new JwtSecurityToken( issuer: _configuration.Issuer, audience: _configuration.Audience, claims: claims, notBefore: now, expires: now.Add(expiration ?? _configuration.Expiration), signingCredentials: _configuration.SigningCredentials ); return new JwtSecurityTokenHandler().WriteToken(jwtSecurityToken); }
2. Startup里的IdentityServer与认证配置
Startup中同时注册了IdentityServer和Authentication服务,但两边的令牌验证规则看起来不统一:
services.AddIdentityServer() .AddDeveloperSigningCredential() .AddInMemoryIdentityResources(IdentityServerConfig.GetIdentityResources()) .AddInMemoryApiResources(IdentityServerConfig.GetApiResources()) .AddInMemoryClients(IdentityServerConfig.GetClients()) .AddAbpPersistedGrants<IAbpPersistedGrantDbContext>() .AddAbpIdentityServer<User>(); services.AddAuthentication().AddIdentityServerAuthentication("IdentityBearer", options => { options.Authority = "http://localhost:62114/"; options.RequireHttpsMetadata = false; });
3. 两种客户端的令牌获取方式
- Angular客户端:直接调用上面的
CreateAccessToken接口生成JWT令牌 - API客户端:通过IdentityServer的令牌端点获取,代码如下:
var disco = await DiscoveryClient.GetAsync("http://localhost:21021"); var httpHandler = new HttpClientHandler(); httpHandler.CookieContainer.Add(new Uri("http://localhost:21021/"), new Cookie(MultiTenancyConsts.TenantIdResolveKey, "1")); // 设置租户ID var tokenClient = new TokenClient(disco.TokenEndpoint, "AngularSPA", "secret", httpHandler); var tokenResponse = await tokenClient.RequestResourceOwnerPasswordAsync("admin", "123qwe", "default-api"); // 也试过RequestClientCredentialsAsync
当前遇到的困境
现在的情况是两种令牌只能有一个能通过认证,要么Angular的能用,要么API客户端的能用,没办法同时支持。我之前参考过双认证的相关方案,但还是没解决问题,想请各位大佬给点建议,看看哪里配置错了或者有没有其他可行的方案。
内容的提问来源于stack exchange,提问作者Tuğrul Karakaya
相关产品推荐
相关产品推荐

