You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用SignOutAsync登出时出错:无法重定向到结束会话端点,配置异常

解决OIDC登出时无法重定向到结束会话端点的问题

Hey there, let's tackle this logout redirect issue you're facing with OIDC in ASP.NET Core. The error you're seeing usually happens because the OIDC middleware can't locate the identity provider's end session endpoint—either because the configuration is incomplete, or the necessary settings are missing. Let's break down the fixes step by step:

1. 完善OIDC认证服务配置

Your current authentication setup cuts off mid-way, so let's make sure the OpenID Connect options are fully configured. The key here is ensuring the middleware can discover (or is explicitly told about) the end session endpoint from your identity provider (IDP).

Here's a complete example of how to set this up:

services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = "oidc";
})
.AddCookie()
.AddOpenIdConnect("oidc", options =>
{
    // 替换为你的IDP的基础地址(比如IdentityServer、Azure AD等)
    options.Authority = "https://your-identity-provider-url"; 
    options.ClientId = "your-registered-client-id";
    options.ClientSecret = "your-client-secret"; // 如果用的是机密客户端
    options.ResponseType = "code";
    
    // 必须包含openid scope才能触发OIDC流程
    options.Scope.Add("openid");
    options.Scope.Add("profile"); // 可选,根据你的需求
    
    // 保存token到cookie,这样登出时能传递必要的信息给IDP
    options.SaveTokens = true;
    
    // 配置登出后的回调路径,这个路径需要在你的IDP后台添加为允许的回调地址
    options.SignedOutCallbackPath = "/signout-callback-oidc";
    
    // 如果你的IDP的元数据(/.well-known/openid-configuration)里没有end_session_endpoint,
    // 可以手动指定它的地址:
    // options.EndSessionEndpoint = "https://your-identity-provider-url/connect/endsession";
});

2. 更新登出方法,添加认证属性

Your current LogOut method is missing the AuthenticationProperties that tell the OIDC middleware where to redirect after a successful logout. Let's adjust that:

public async Task LogOut()
{
    // 先清除本地Cookie认证会话
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
    
    // 配置登出后的重定向地址(比如首页)
    var logoutProperties = new AuthenticationProperties
    {
        RedirectUri = "/"
    };
    
    // 触发OIDC登出流程,传递配置的属性
    await HttpContext.SignOutAsync("oidc", logoutProperties);
}

3. 关键检查点

  • Verify IDP Metadata: Visit your IDP's metadata endpoint ({Authority}/.well-known/openid-configuration) and confirm it includes the end_session_endpoint field. If it doesn't, you'll need to either fix your IDP's configuration or manually set options.EndSessionEndpoint as shown above.
  • Allowed Callback URLs: Make sure the SignedOutCallbackPath (e.g., /signout-callback-oidc) is added to your IDP's list of allowed redirect/logout URLs. Most IDPs block unapproved redirects for security.
  • SaveTokens Setting: Ensure options.SaveTokens = true is enabled—this lets the middleware access the id_token needed to properly trigger the IDP's end session flow.

内容的提问来源于stack exchange,提问作者chridam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 03:32:38