Identity Server 4登出报错:/connect/endsession提示资源已移除或不可用
解决Identity Server 4登出时/connect/endsession报错的问题
我碰到过好几个朋友遇到这个登出报错的问题,咱们一步步排查最常见的原因和解决办法:
1. 先确认IdentityServer是否启用了EndSession端点
IdentityServer默认是开启这个端点的,但如果手动修改过端点配置,可能不小心把它禁用了。去IdentityServer项目的Startup.cs里检查:
public void ConfigureServices(IServiceCollection services) { // 其他配置... services.AddIdentityServer() .AddInMemoryClients(Config.Clients) .AddInMemoryIdentityResources(Config.IdentityResources) .AddInMemoryApiScopes(Config.ApiScopes) .AddTestUsers(TestUsers.Users); } public void Configure(IApplicationBuilder app) { // 其他中间件... app.UseIdentityServer(); // 如果手动用了UseEndpoints,一定要加这句映射IdentityServer端点 app.UseEndpoints(endpoints => { endpoints.MapDefaultControllerRoute(); endpoints.MapIdentityServer(); // 这个不能丢! }); }
要是你手动配置过端点开关,得确保这两个选项是开启的:
services.AddIdentityServer(options => { options.Endpoints.EnableEndSessionEndpoint = true; options.Endpoints.EnableEndSessionCallbackEndpoint = true; }) // ...后续配置
2. 重点检查客户端的PostLogoutRedirectUris配置
这个是最容易踩坑的点!IdentityServer登出后需要知道跳回哪里,如果客户端配置里没加对应地址,或者地址不匹配,就会出问题。
第一步:在IdentityServer的客户端配置里添加正确地址
比如你的MVC客户端登出回调地址是https://your-client.com/signout-callback-oidc,要在Config的Clients里补上:
new Client { ClientId = "mvc-client", ClientName = "MVC Client", AllowedGrantTypes = GrantTypes.Code, ClientSecrets = { new Secret("your-secret".Sha256()) }, RedirectUris = { "https://your-client.com/signin-oidc" }, // 这里必须包含客户端登出后的回调地址 PostLogoutRedirectUris = { "https://your-client.com/signout-callback-oidc" }, AllowedScopes = { "openid", "profile" }, AllowOfflineAccess = true }
第二步:优化客户端的登出代码
最好显式指定重定向地址,避免自动生成的地址和配置不匹配:
public async Task<IActionResult> Logout() { await HttpContext.SignOutAsync("Cookies"); // 显式指定重定向地址,和IdentityServer配置的一致 return SignOut(new AuthenticationProperties { RedirectUri = "/" }, "oidc"); }
3. 确认客户端的OpenID Connect配置正确
客户端的Startup.cs里配置AddOpenIdConnect时,要保证回调路径和登出配置没问题:
services.AddAuthentication(options => { options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookies") .AddOpenIdConnect("oidc", options => { options.Authority = "https://identity.acme.com"; options.ClientId = "mvc-client"; options.ClientSecret = "your-secret"; options.ResponseType = "code"; options.SaveTokens = true; // 这个路径要和IdentityServer里PostLogoutRedirectUris的地址一致 options.SignedOutCallbackPath = "/signout-callback-oidc"; // 可以自定义登出后的跳转逻辑 options.Events = new OpenIdConnectEvents { OnSignedOutCallbackRedirect = context => { context.Response.Redirect("/"); context.HandleResponse(); return Task.CompletedTask; } }; });
4. 检查IdentityServer的中间件顺序
中间件顺序错了也会导致端点无法被路由到,要确保UseIdentityServer在UseRouting、UseAuthentication、UseAuthorization之后,UseEndpoints之前:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.UseIdentityServer(); // 这个顺序很关键! app.UseEndpoints(endpoints => { endpoints.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); }); }
5. 最后排查URL拼写和HTTPS问题
- 确认
https://identity.acme.com地址拼写正确,服务正常运行; - 确保客户端和IdentityServer都用HTTPS,部分浏览器会阻止HTTP的重定向请求,导致端点访问失败。
建议先从第2点开始排查,大部分情况都是因为漏配置PostLogoutRedirectUris导致的。
内容的提问来源于stack exchange,提问作者Fanetic
相关产品推荐
相关产品推荐

