You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Identity Server 4登出报错:/connect/endsession提示资源已移除或不可用

解决Identity Server 4登出时/connect/endsession报错的问题

我碰到过好几个朋友遇到这个登出报错的问题,咱们一步步排查最常见的原因和解决办法:

1. 先确认IdentityServer是否启用了EndSession端点

IdentityServer默认是开启这个端点的,但如果手动修改过端点配置,可能不小心把它禁用了。去IdentityServer项目的Startup.cs里检查:

public void ConfigureServices(IServiceCollection services)
{
    // 其他配置...
    services.AddIdentityServer()
        .AddInMemoryClients(Config.Clients)
        .AddInMemoryIdentityResources(Config.IdentityResources)
        .AddInMemoryApiScopes(Config.ApiScopes)
        .AddTestUsers(TestUsers.Users);
}

public void Configure(IApplicationBuilder app)
{
    // 其他中间件...
    app.UseIdentityServer();
    // 如果手动用了UseEndpoints,一定要加这句映射IdentityServer端点
    app.UseEndpoints(endpoints =>
    {
        endpoints.MapDefaultControllerRoute();
        endpoints.MapIdentityServer(); // 这个不能丢!
    });
}

要是你手动配置过端点开关,得确保这两个选项是开启的:

services.AddIdentityServer(options =>
{
    options.Endpoints.EnableEndSessionEndpoint = true;
    options.Endpoints.EnableEndSessionCallbackEndpoint = true;
})
// ...后续配置

2. 重点检查客户端的PostLogoutRedirectUris配置

这个是最容易踩坑的点!IdentityServer登出后需要知道跳回哪里,如果客户端配置里没加对应地址,或者地址不匹配,就会出问题。

第一步:在IdentityServer的客户端配置里添加正确地址

比如你的MVC客户端登出回调地址是https://your-client.com/signout-callback-oidc,要在Config的Clients里补上:

new Client
{
    ClientId = "mvc-client",
    ClientName = "MVC Client",
    AllowedGrantTypes = GrantTypes.Code,
    ClientSecrets = { new Secret("your-secret".Sha256()) },
    RedirectUris = { "https://your-client.com/signin-oidc" },
    // 这里必须包含客户端登出后的回调地址
    PostLogoutRedirectUris = { "https://your-client.com/signout-callback-oidc" },
    AllowedScopes = { "openid", "profile" },
    AllowOfflineAccess = true
}

第二步:优化客户端的登出代码

最好显式指定重定向地址,避免自动生成的地址和配置不匹配:

public async Task<IActionResult> Logout()
{
    await HttpContext.SignOutAsync("Cookies");
    // 显式指定重定向地址,和IdentityServer配置的一致
    return SignOut(new AuthenticationProperties
    {
        RedirectUri = "/"
    }, "oidc");
}

3. 确认客户端的OpenID Connect配置正确

客户端的Startup.cs里配置AddOpenIdConnect时,要保证回调路径和登出配置没问题:

services.AddAuthentication(options =>
{
    options.DefaultScheme = "Cookies";
    options.DefaultChallengeScheme = "oidc";
})
.AddCookie("Cookies")
.AddOpenIdConnect("oidc", options =>
{
    options.Authority = "https://identity.acme.com";
    options.ClientId = "mvc-client";
    options.ClientSecret = "your-secret";
    options.ResponseType = "code";
    options.SaveTokens = true;
    // 这个路径要和IdentityServer里PostLogoutRedirectUris的地址一致
    options.SignedOutCallbackPath = "/signout-callback-oidc";
    // 可以自定义登出后的跳转逻辑
    options.Events = new OpenIdConnectEvents
    {
        OnSignedOutCallbackRedirect = context =>
        {
            context.Response.Redirect("/");
            context.HandleResponse();
            return Task.CompletedTask;
        }
    };
});

4. 检查IdentityServer的中间件顺序

中间件顺序错了也会导致端点无法被路由到,要确保UseIdentityServer在UseRouting、UseAuthentication、UseAuthorization之后,UseEndpoints之前:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }

    app.UseHttpsRedirection();
    app.UseStaticFiles();

    app.UseRouting();

    app.UseAuthentication();
    app.UseAuthorization();

    app.UseIdentityServer(); // 这个顺序很关键!

    app.UseEndpoints(endpoints =>
    {
        endpoints.MapControllerRoute(
            name: "default",
            pattern: "{controller=Home}/{action=Index}/{id?}");
    });
}

5. 最后排查URL拼写和HTTPS问题

  • 确认https://identity.acme.com地址拼写正确,服务正常运行;
  • 确保客户端和IdentityServer都用HTTPS,部分浏览器会阻止HTTP的重定向请求,导致端点访问失败。

建议先从第2点开始排查,大部分情况都是因为漏配置PostLogoutRedirectUris导致的。

内容的提问来源于stack exchange,提问作者Fanetic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 04:07:12