You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何刷新Access Token?基于ASP.NET Core 2.0与Identity Server 4场景

ASP.NET Core 2.0 结合Identity Server 4的身份验证配置示例

我最近在开发一个ASP.NET Core 2.0 Web应用,这套系统是通过Identity Server 4来完成身份验证流程的,同时还关联了一个需要以Bearer Token形式使用Access Token来访问的API。下面是我在Startup类里的身份验证相关配置代码:

services.AddAuthentication(options => 
{ 
    options.DefaultScheme = "Cookies"; 
    options.DefaultChallengeScheme = "oidc"; 
}) 
.AddCookie("Cookies") 
.AddOpenIdConnect("oidc", options => 
{ 
    options.SignInScheme = "Cookies"; 
    options.Authority = idsEndPoint; 
    options.RequireHttpsMetadata = false; 
    // 其他配置项...
});

这里简单拆解下几个关键配置点:

  • 将"Cookies"设为默认认证Scheme,负责管理本地用户会话
  • 将"oidc"设为默认挑战Scheme,当需要用户登录时,会引导到Identity Server 4的授权页面
  • AddCookie("Cookies"):注册Cookie认证方案,用来在本地存储用户的身份信息
  • AddOpenIdConnect("oidc"):配置OpenID Connect协议对接Identity Server 4,其中Authority指定了Identity Server的地址,RequireHttpsMetadata在开发环境可以暂时设为false(生产环境务必开启HTTPS并设为true)

内容的提问来源于stack exchange,提问作者Linda Lawton - DaImTo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 04:04:52