如何将OAuthIntrospectionConstants.ClientSecretPost添加至指定认证配置?
解决方案
1. 添加ClientSecretPost到支持的认证方法列表
在你的项目Startup.cs的ConfigureServices方法中,配置OAuth Introspection时直接修改IntrospectionEndpointAuthMethodsSupported集合即可:
public void ConfigureServices(IServiceCollection services) { services.AddAuthentication(options => { options.DefaultAuthenticateScheme = OAuthIntrospectionDefaults.AuthenticationScheme; options.DefaultChallengeScheme = OAuthIntrospectionDefaults.AuthenticationScheme; }) .AddOAuthIntrospection(options => { options.ClientId = "你的客户端ID"; options.ClientSecret = "你的客户端密钥"; // 添加上ClientSecretPost options.IntrospectionEndpointAuthMethodsSupported.Add( OAuthIntrospectionConstants.ClientAuthenticationMethods.ClientSecretPost); options.IntrospectionEndpoint = "你的授权服务器introspect端点地址"; }); // 其他服务配置代码... }
如果发现IntrospectionEndpointAuthMethodsSupported是只读集合(早期版本可能存在这种情况),可以直接初始化一个包含默认方法和ClientSecretPost的新集合:
options.IntrospectionEndpointAuthMethodsSupported = new HashSet<string> { OAuthIntrospectionConstants.ClientAuthenticationMethods.ClientSecretBasic, OAuthIntrospectionConstants.ClientAuthenticationMethods.ClientSecretPost };
2. 关于GetIntrospectionPayloadAsync方法仅显示第二个分支的问题
你遇到的PDB缺失分支的情况,主要有两个原因:
- 你使用的是Release版本的NuGet包,Release版的PDB会精简调试信息,部分分支的调试符号会被移除;
- 你查看的是GitHub上的
dev分支代码,但.NET Core 1.0对应的是该库的1.0.x稳定版本,代码结构和dev分支存在差异,分支逻辑自然也不一样。
想要获取完整的调试信息,可以尝试这两个办法:
- 前往GitHub切换到对应1.0.x的标签分支(比如
1.0.0)查看代码,确认该方法的实际结构; - 直接克隆项目代码,编译Debug版本的程序集替换NuGet包引用,这样就能拿到完整的PDB调试符号。
额外提醒
.NET Core 1.0版本的AspNet.Security.OAuth.Introspection和后续版本的配置逻辑存在差异,如果找不到IntrospectionEndpointAuthMethodsSupported属性,要确保你引用的是AspNet.Security.OAuth.Introspection的1.0.x版本。
内容的提问来源于stack exchange,提问作者Aleksey Khorev
相关产品推荐
相关产品推荐

