IdentityServer4发现文档URL含双反斜杠致客户端认证失败
I’ve run into this exact issue before—when your IdentityServer4 instance outputs well-known config URLs with an extra backslash in the schema (like \http://...), MVC clients choke trying to parse those invalid URLs. Let’s break down how to diagnose and fix this:
Common Causes & Step-by-Step Solutions
1. Explicitly Set the IdentityServer Issuer URI
The most frequent culprit is incorrect auto-generated issuer URI. IdentityServer sometimes guesses the base URL wrong (especially behind proxies or non-standard hosting). Force it explicitly in your Startup.cs to override auto-generation:
services.AddIdentityServer(options => { // Hardcode the valid public issuer URL to avoid formatting errors options.IssuerUri = "http://www.server.meetcorepoint.com"; }) .AddInMemoryClients(Config.Clients) .AddInMemoryApiScopes(Config.ApiScopes) // Add your identity store and other required services here
2. Validate MVC Client Configuration
Double-check your MVC client’s setup to ensure the Authority value has no stray backslashes. It should be a clean, valid URL:
services.AddAuthentication(options => { options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookies") .AddOpenIdConnect("oidc", options => { options.Authority = "http://www.server.meetcorepoint.com"; // No backslashes allowed here! options.ClientId = "your-mvc-client-id"; options.ClientSecret = "your-client-secret"; options.ResponseType = "code"; // Rest of your client configuration });
3. Fix Proxy/Load Balancer Header Forwarding (If Applicable)
If your IdentityServer is behind a reverse proxy or load balancer, missing or misconfigured forwarded headers can cause malformed URL generation. Add this middleware to your IdentityServer’s pipeline before UseIdentityServer:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { // Forward headers so IdentityServer uses the public URL instead of internal container addresses app.UseForwardedHeaders(new ForwardedHeadersOptions { ForwardedHeaders = ForwardedHeaders.XForwardedProto | ForwardedHeaders.XForwardedHost }); // Rest of your pipeline setup app.UseIdentityServer(); }
4. Verify the Well-Known Config Directly
Visit http://www.server.meetcorepoint.com/.well-known/openid-configuration in your browser. If any endpoint URLs start with \http://, that confirms the formatting issue. After applying fixes, refresh this endpoint to ensure URLs are now valid (no leading backslashes).
Why This Error Occurs
The "Unable to parse host name" exception happens because the client’s OpenID Connect handler can’t recognize URLs with a leading backslash in the schema. A URL like \http://www.server.meetcorepoint.com/connect/token isn’t a valid HTTP URL, so the handler fails to resolve the host.
内容的提问来源于stack exchange,提问作者Dejan Bogatinovski

