You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 2 MVC客户端+IdentityServer4获取外部用户AccessToken问题咨询

Troubleshooting Authentication Scheme Conflicts in .NET Core 2 MVC + IdentityServer4

Hey there! Let's work through the issue you're hitting with your authentication setup. When you added options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme to your AddAuthentication configuration, you likely ran into a conflict because of how .NET Core 2.x handles default authentication schemes.

Why the Exception Happens

In .NET Core 2.x, the DefaultScheme acts as a fallback for all other default scheme types (Authenticate, Challenge, SignIn, SignOut) if they aren't explicitly set. When you explicitly set DefaultAuthenticateScheme while already having DefaultScheme pointed to the cookie scheme, you're creating redundant configuration that can confuse the authentication pipeline. This often leads to exceptions like conflicting scheme registrations or missing handler errors.

Correct Configuration for Your Scenario

For an MVC client integrating with IdentityServer4 (especially when you need to retrieve external user access tokens), here's the standard, working configuration you should use:

services.AddAuthentication(options =>
{
    // Default scheme for all auth operations (authenticate, sign-in/sign-out) is the cookie
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    // When we need to challenge the user (redirect to login), use OIDC
    options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
})
// Register the cookie authentication handler
.AddCookie(CookieAuthenticationDefaults.AuthenticationScheme)
// Register the OpenID Connect handler for interacting with IdentityServer4
.AddOpenIdConnect(OpenIdConnectDefaults.AuthenticationScheme, options =>
{
    options.Authority = "https://your-identityserver-instance-url";
    options.ClientId = "your-mvc-client-id";
    options.ClientSecret = "your-client-secret"; // Required if using Authorization Code flow
    options.ResponseType = "code id_token"; // Hybrid flow (common for MVC apps)
    options.SaveTokens = true; // Critical: saves access/refresh/id tokens to the cookie
    // Add scopes for the resources you need access to
    options.Scope.Add("openid");
    options.Scope.Add("profile");
    options.Scope.Add("your-target-api-scope");
});

Key Notes for Retrieving the Access Token

Once your configuration is fixed, you can easily fetch the access token in your controller actions using:

var accessToken = await HttpContext.GetTokenAsync("access_token");

Just make sure options.SaveTokens = true is set in your OIDC configuration—this tells the handler to persist the tokens in the authentication cookie so you can retrieve them later.

Additional Troubleshooting Steps

If you still encounter exceptions after adjusting the configuration:

  • Verify app.UseAuthentication() is called in your Configure method (it must come before app.UseMvc()).
  • Ensure both the cookie and OIDC authentication handlers are properly registered with their respective scheme names.
  • Check the exact exception message—common issues include "No authentication handler registered for scheme" (if you misspell a scheme name) or scheme conflicts (if you set conflicting defaults).

内容的提问来源于stack exchange,提问作者Saifal Maluk

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:58:31