使用IdentityServer与oidc-client时signinSilentCallback返回user未定义
I've completed user authentication via MVC, but when using signinSilentCallback from oidc-client in JavaScript to get user details, the returned user is undefined and no errors are thrown. Here's my relevant code:
JavaScript Code
var mgr = new UserManager({ authority: "http://localhost:5000", client_id: "js", redirect_uri: "http://localhost:50144/signin-oidc", silent_redirect_uri: "http://localhost:50144/signin-oidc", response_type: "id_token token", post_logout_redirect_uri: "http://localhost:50144/signout-callback-oidc", }); mgr.signinSilentCallback().then(function (user) { //**Here user is undefined.** axios.defaults.headers.common['Authorization'] = "Bearer " + user.access_token; });
IdentityServer4 Client Configuration
new Client { ClientId = "js", ClientName = "js", ClientUri = "http://localhost:50144", AllowedGrantTypes = GrantTypes.Implicit, AllowAccessTokensViaBrowser = true, RequireClientSecret = false, AccessTokenType = AccessTokenType.Jwt, RedirectUris = { "http://localhost:50144/signin-oidc", }, PostLogoutRedirectUris = { "http://localhost:50144/signout-callback-oidc" }, AllowedCorsOrigins = { "http://localhost:50144" }, AllowedScopes = { IdentityServerConstants.StandardScopes.OpenId, IdentityServerConstants.StandardScopes.Profile, IdentityServerConstants.StandardScopes.Email } }
Possible Fixes & Explanations
Let's walk through the most likely issues and how to resolve them:
1. You're Using signinSilentCallback Wrong
signinSilentCallback() is only meant to handle the response from a silent authentication flow—meaning you first have to call signinSilent() to initiate that flow. Since you authenticated via MVC (server-side), you didn't trigger a silent login, so this method has no response to process, hence returning undefined.
If you want to fetch an existing authenticated user session (stored in the browser by oidc-client), use getUser() instead:
mgr.getUser().then(function(user) { if (user) { axios.defaults.headers.common['Authorization'] = "Bearer " + user.access_token; } else { console.log("No authenticated user found in browser storage"); // You might need to redirect to login or handle unauthenticated state here } });
2. Shared Redirect URI is Causing Conflicts
You're using the same URI for both normal login redirect and silent redirect. This can lead to conflicts with your MVC app's existing code on that page. It's best practice to create a dedicated blank page for silent renewals (e.g., silent-renew.html):
<!DOCTYPE html> <html> <head> <title>Silent Renew</title> </head> <body> <script src="oidc-client.min.js"></script> <script> new Oidc.UserManager().signinSilentCallback(); </script> </body> </html>
Update your UserManager config to use this new URI:
silent_redirect_uri: "http://localhost:50144/silent-renew.html",
And add it to your IdentityServer4 client's allowed redirect URIs:
RedirectUris = { "http://localhost:50144/signin-oidc", "http://localhost:50144/silent-renew.html" },
3. Check for Hidden Errors (Even if None Are Visible)
Open your browser's DevTools to dig deeper:
- Go to the Network tab and check if requests to IdentityServer's
authorizeortokenendpoints are failing silently (e.g., CORS issues, 400-level errors). - Check the Console tab for suppressed warnings about storage access or session issues.
4. Ensure Session Persistence Between MVC and oidc-client
MVC's server-side authentication might not be writing the user session to the browser storage that oidc-client uses (default is sessionStorage). If that's the case, oidc-client has no way to detect the authenticated user. You may need to:
- Initialize the oidc-client session manually after server-side authentication (e.g., by passing the token from MVC to your JS code), or
- Use a shared authentication mechanism that syncs server and client sessions.
内容的提问来源于stack exchange,提问作者Anonymous Creator

