You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET MVC中如何通过Identity框架从OAuth2获取AccessToken?

在MVC项目中获取AccessToken的解决方案

我来帮你解决这个问题——在Web API里用http://localhost:port/token拿AccessToken的方式,在MVC项目里其实可以通过几种方式实现,我给你拆解一下可行的方案:

方案1:在MVC项目中配置原生OAuth Token端点

如果你的MVC项目和之前的Web API是同类型(比如都是.NET Framework或ASP.NET Core),可以直接在项目里配置OAuth授权中间件,生成/token端点:

针对.NET Framework MVC(OWIN)

  1. 确保项目已安装Microsoft.Owin.Security.OAuth和Microsoft.Owin.Security.Cookies NuGet包。
  2. 在Startup.Auth.cs里配置OAuth选项:
public void ConfigureAuth(IAppBuilder app)
{
    var oAuthOptions = new OAuthAuthorizationServerOptions
    {
        TokenEndpointPath = new PathString("/token"),
        Provider = new ApplicationOAuthProvider(), // 自定义授权提供者,实现用户验证逻辑
        AccessTokenExpireTimeSpan = TimeSpan.FromDays(1),
        AllowInsecureHttp = true // 开发环境可用,生产环境需改为false
    };

    // 启用Bearer令牌认证
    app.UseOAuthBearerTokens(oAuthOptions);
}
  1. 实现ApplicationOAuthProvider类,重写GrantResourceOwnerCredentials方法来验证用户名密码并发放令牌。

针对ASP.NET Core MVC

  1. 安装Microsoft.AspNetCore.Authentication.JwtBearer NuGet包。
  2. 在Program.cs里配置认证服务:
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidateAudience = true,
            ValidateLifetime = true,
            ValidateIssuerSigningKey = true,
            ValidIssuer = builder.Configuration["Jwt:Issuer"],
            ValidAudience = builder.Configuration["Jwt:Audience"],
            IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(builder.Configuration["Jwt:Key"]))
        };
    });

// 别忘了添加授权服务
builder.Services.AddAuthorization();
  1. 创建一个Token控制器来模拟/token端点:
[Route("token")]
[ApiController]
public class TokenController : ControllerBase
{
    private readonly IConfiguration _config;

    public TokenController(IConfiguration config)
    {
        _config = config;
    }

    [HttpPost]
    public IActionResult GetToken([FromForm] LoginRequest request)
    {
        // 替换为你的用户验证逻辑
        if (request.Username == "demo" && request.Password == "demo123")
        {
            var securityKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(_config["Jwt:Key"]));
            var credentials = new SigningCredentials(securityKey, SecurityAlgorithms.HmacSha256);

            var token = new JwtSecurityToken(
                issuer: _config["Jwt:Issuer"],
                audience: _config["Jwt:Audience"],
                expires: DateTime.Now.AddMinutes(30),
                signingCredentials: credentials);

            return Ok(new
            {
                access_token = new JwtSecurityTokenHandler().WriteToken(token),
                token_type = "bearer",
                expires_in = 1800
            });
        }

        return Unauthorized("Invalid credentials");
    }

    public class LoginRequest
    {
        public string Username { get; set; }
        public string Password { get; set; }
        public string Grant_Type { get; set; } = "password";
    }
}

这样你就可以通过POST http://localhost:mvc-port/token,用表单提交username、password和grant_type来获取AccessToken了。

方案2:直接调用现有Web API的Token端点

如果你的MVC项目和Web API是分开部署的,最简单的方式就是在MVC里用HttpClient请求Web API的/token端点:

public async Task<string> GetAccessTokenFromApi()
{
    using var client = new HttpClient();
    var formData = new FormUrlEncodedContent(new[]
    {
        new KeyValuePair<string, string>("grant_type", "password"),
        new KeyValuePair<string, string>("username", "your-username"),
        new KeyValuePair<string, string>("password", "your-password"),
        // 如果Web API需要client_id和client_secret,也要加上
        new KeyValuePair<string, string>("client_id", "your-client-id")
    });

    var response = await client.PostAsync("http://localhost:api-port/token", formData);
    if (response.IsSuccessStatusCode)
    {
        var tokenResponse = await response.Content.ReadFromJsonAsync<TokenResponse>();
        return tokenResponse.AccessToken;
    }

    throw new Exception("Failed to get access token");
}

public class TokenResponse
{
    [JsonPropertyName("access_token")]
    public string AccessToken { get; set; }
    [JsonPropertyName("token_type")]
    public string TokenType { get; set; }
    [JsonPropertyName("expires_in")]
    public int ExpiresIn { get; set; }
}

注意:如果Web API和MVC跨域,需要在Web API里配置CORS允许MVC的域名访问。

一些额外提示

  • 不管用哪种方案,生产环境一定要使用HTTPS,避免令牌被窃取。
  • 如果用JWT,要妥善保管签名密钥,不要硬编码在代码里,建议用配置文件或密钥管理服务存储。

内容的提问来源于stack exchange,提问作者Ibtisam

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 06:58:36