IdentityServer3身份项目无法获取令牌技术求助
Hey there! Let's dig into why you're having trouble getting tokens in your IdentityServer3 project while other apps work fine. Looking at your code, I spot a few potential issues to check:
1. Critical Bug in User List Population
Your Users.Get() method creates InMemoryUser objects in a loop, but never adds them to the UsersList! This means IdentityServer has no user data to authenticate against—so no tokens can be issued.
Fix this by adding the created user to the list inside your foreach loop:
IdentityContext db = new IdentityContext(); var AllUsers = db.Users.ToList(); List<InMemoryUser> UsersList = new List<InMemoryUser>(); foreach (var item in AllUsers) { InMemoryUser UserInMemory = new InMemoryUser(); UserInMemory.Username = item.UserName; UserInMemory.Password = item.Password; UserInMemory.Subject = item.Id.ToString(); UserInMemory.Claims = new Claim[] { new Claim(Constants.ClaimTypes.PreferredUserName, item.UserName), // Add role claims here if your users have roles new Claim(Constants.ClaimTypes.Role, item.Role) }; // This line was missing! UsersList.Add(UserInMemory); } return UsersList;
2. Conflicting User Service Configuration
In your Startup code, you're configuring both in-memory users and a custom UserService:
var factory = new IdentityServerServiceFactory() .UseInMemoryClients(Clients.Get()) .UseInMemoryScopes(Scopes.Get()) .UseInMemoryUsers(Users.Get()); // In-memory users var userService = new UserService(); factory.UserService = new Registration<IUserService>(reslove => userService); // Custom user service
These two configurations conflict. Pick one:
- If you want to use in-memory users, remove the custom
UserServiceregistration lines. - If you need the custom
UserService, remove the.UseInMemoryUsers(Users.Get())call, and ensure yourUserServicecorrectly implements theIUserServiceinterface (especially theAuthenticateLocalAsyncmethod for password validation).
3. Verify Redirect URI Exact Match
IdentityServer enforces strict matching for redirect URIs. Double-check that the redirect URI your Identity project uses (when requesting tokens) is exactly https://localhost:44396/—including the trailing slash, HTTPS protocol, and correct port. Even a tiny mismatch (like missing a slash or using HTTP instead of HTTPS) will block token issuance.
4. Check Logs for Detailed Errors
You've already set up Serilog logging—head to c:\logs\IdSvrAdmin-{Date}.log and look for error messages. IdentityServer logs every detail of authentication failures (e.g., "user not found", "invalid redirect URI", "scope not allowed")—this will be your most reliable tool for pinpointing issues.
5. Confirm Scope Configuration
Your scope setup looks mostly okay, but ensure:
- The
WebAPIscope is marked asScopeType.Resource(which it is), and your client includes it in the requested scopes. - If your users need role claims, make sure you're adding the
roleclaim to yourInMemoryUserobjects (as shown in the fixed user list code above).
Start with fixing the user list population bug first—that's the most obvious blocker. Then check the user service conflict and logs, and you should be able to resolve the token issue.
内容的提问来源于stack exchange,提问作者Mohsen

