You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer3身份项目无法获取令牌技术求助

Hey there! Let's dig into why you're having trouble getting tokens in your IdentityServer3 project while other apps work fine. Looking at your code, I spot a few potential issues to check:

1. Critical Bug in User List Population

Your Users.Get() method creates InMemoryUser objects in a loop, but never adds them to the UsersList! This means IdentityServer has no user data to authenticate against—so no tokens can be issued.

Fix this by adding the created user to the list inside your foreach loop:

IdentityContext db = new IdentityContext();
var AllUsers = db.Users.ToList();
List<InMemoryUser> UsersList = new List<InMemoryUser>();
foreach (var item in AllUsers) {
    InMemoryUser UserInMemory = new InMemoryUser();
    UserInMemory.Username = item.UserName;
    UserInMemory.Password = item.Password;
    UserInMemory.Subject = item.Id.ToString();
    UserInMemory.Claims = new Claim[] { 
        new Claim(Constants.ClaimTypes.PreferredUserName, item.UserName),
        // Add role claims here if your users have roles
        new Claim(Constants.ClaimTypes.Role, item.Role) 
    };
    // This line was missing!
    UsersList.Add(UserInMemory);
}
return UsersList;

2. Conflicting User Service Configuration

In your Startup code, you're configuring both in-memory users and a custom UserService:

var factory = new IdentityServerServiceFactory()
    .UseInMemoryClients(Clients.Get())
    .UseInMemoryScopes(Scopes.Get())
    .UseInMemoryUsers(Users.Get()); // In-memory users
var userService = new UserService();
factory.UserService = new Registration<IUserService>(reslove => userService); // Custom user service

These two configurations conflict. Pick one:

  • If you want to use in-memory users, remove the custom UserService registration lines.
  • If you need the custom UserService, remove the .UseInMemoryUsers(Users.Get()) call, and ensure your UserService correctly implements the IUserService interface (especially the AuthenticateLocalAsync method for password validation).

3. Verify Redirect URI Exact Match

IdentityServer enforces strict matching for redirect URIs. Double-check that the redirect URI your Identity project uses (when requesting tokens) is exactly https://localhost:44396/—including the trailing slash, HTTPS protocol, and correct port. Even a tiny mismatch (like missing a slash or using HTTP instead of HTTPS) will block token issuance.

4. Check Logs for Detailed Errors

You've already set up Serilog logging—head to c:\logs\IdSvrAdmin-{Date}.log and look for error messages. IdentityServer logs every detail of authentication failures (e.g., "user not found", "invalid redirect URI", "scope not allowed")—this will be your most reliable tool for pinpointing issues.

5. Confirm Scope Configuration

Your scope setup looks mostly okay, but ensure:

  • The WebAPI scope is marked as ScopeType.Resource (which it is), and your client includes it in the requested scopes.
  • If your users need role claims, make sure you're adding the role claim to your InMemoryUser objects (as shown in the fixed user list code above).

Start with fixing the user list population bug first—that's the most obvious blocker. Then check the user service conflict and logs, and you should be able to resolve the token issue.

内容的提问来源于stack exchange,提问作者Mohsen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:57:54