IdentityServer4引用令牌存储位置及重启后有效性问询
1. Where does IdentityServer4 store reference tokens?
By default, IdentityServer4 stores reference tokens in an in-memory cache (backed by the IMemoryCache service). This is transient storage—tokens only exist while the IdentityServer instance is running and are lost when the service restarts or scales to new instances.
For persistent storage (so tokens survive restarts or work across multiple IdentityServer nodes), you have two primary options:
- Use the official Entity Framework integration: This stores reference tokens (and other persisted grants like refresh tokens) in a database, typically in a
PersistedGrantstable. - Implement your own
IPersistedGrantStore: This interface defines methods for storing, retrieving, and deleting persisted grants. You can plug in any storage system you prefer—like Redis, a custom SQL database, or a NoSQL store—by implementing these methods.
2. Will a reference token remain valid after IdentityServer4 restarts? (And how to fix if not)
Short answer: By default, no—it will be invalid.
Here's the breakdown:
When using the default in-memory store, all reference tokens are cleared when IdentityServer restarts. When a client sends the reference token for validation, IdentityServer checks its store to confirm the token exists, hasn't expired, and is still valid. Since the in-memory store is empty after a restart, it can't locate the token and will reject the request.
Note: Your IResourceOwnerPasswordValidator implementation only handles validating user credentials during login—it doesn't affect how tokens are stored or validated post-login.
How to solve this: Implement a persistent IPersistedGrantStore
To make reference tokens survive restarts, replace the in-memory store with a persistent one:
Implement the
IPersistedGrantStoreinterface: This interface includes methods likeStoreAsync,GetAsync,RemoveAsync, andGetAllAsyncto manage CRUD operations for persisted grants (including reference tokens).- For example, with Redis, you'd write code to save tokens with their expiration time, retrieve them by their unique key, and delete them when they expire or are revoked.
- For a SQL database, create a table to store grant details (like grant key, client ID, user ID, expiration date, grant type) and map the interface methods to database queries.
Register your custom store in dependency injection: Update your IdentityServer startup configuration to use your persistent store instead of the default in-memory one:
services.AddIdentityServer() .AddInMemoryClients(Config.Clients) .AddInMemoryApiResources(Config.ApiResources) .AddResourceOwnerValidator<MyCustomPasswordValidator>() .AddPersistedGrantStore<MyCustomPersistedGrantStore>(); // Register your custom store
Once set up, reference tokens are stored in your persistent system. After a restart, IdentityServer can fetch the token from this store, verify its validity and expiration, and grant access if everything checks out.
内容的提问来源于stack exchange,提问作者eugeneK

