如何将Asp.Net Core MVC应用连接到Identity Server 4?用户存储选项问询
Absolutely! You can connect your local Identity Server 4 (IS4) instance to an ASP.NET Core MVC app created using the "Connect to an existing user store in the cloud" option. Even though the label mentions "cloud," this option is built to work with any standards-compliant OpenID Connect/OAuth2 identity provider—including your self-hosted IS4 setup.
Required Parameters for the Setup Interface
When creating the MVC app via the Visual Studio template or .NET CLI, here’s what you’ll need to input if the template exposes these fields (if not, you can manually configure the code later):
- Identity Provider: Select
OpenID Connect(you may need to expand "Other" or "Custom" options to find this, since default choices are cloud providers like Azure AD). - Client ID: The unique client identifier you registered for your MVC app in your Identity Server 4 instance.
- Client Secret: The secret linked to that client registration in IS4 (only required if your MVC app is set as a confidential client, which is standard for server-side MVC apps).
- Authority: The base URL of your running Identity Server 4 instance (e.g.,
https://localhost:5001). - Callback Path: Defaults to
/signin-oidc—make sure this matches the redirect URI configured for the client in IS4. - Sign-out Callback Path: Defaults to
/signout-callback-oidc—ensure this is listed as a post-logout redirect URI in your IS4 client settings.
Manual Configuration (If Template Doesn’t Expose Fields)
If the template’s UI doesn’t let you input these custom values, you can easily add the configuration manually in your MVC app’s Program.cs:
var builder = WebApplication.CreateBuilder(args); // Add MVC services builder.Services.AddControllersWithViews(); // Configure authentication with IS4 builder.Services.AddAuthentication(options => { options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookies") // Handles session cookies for the MVC app .AddOpenIdConnect("oidc", options => { options.Authority = "https://your-is4-server-url"; // Replace with your IS4 URL options.ClientId = "your-mvc-client-id"; // From IS4 client registration options.ClientSecret = "your-mvc-client-secret"; // From IS4 client registration options.ResponseType = "code"; // Authorization Code flow (best for server-side apps) options.SaveTokens = true; // Persist tokens in the cookie options.Scope.Add("openid"); // Required OpenID Connect scope options.Scope.Add("profile"); // Optional scope for user profile data // Add any custom scopes you've defined in IS4 (e.g., API access) options.Scope.Add("your-custom-api-scope"); }); var app = builder.Build(); // Middleware setup if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Home/Error"); app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); // Important: Add authentication middleware before authorization app.UseAuthentication(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); app.Run();
Practical Resources to Help
- Identity Server4 Official Quickstarts: The "ASP.NET Core MVC Client" quickstart walks you through step-by-step registration and configuration, including client setup in IS4 and MVC app integration.
- ASP.NET Core Authentication Docs: The OpenID Connect authentication section explains each configuration parameter in detail, helping you understand why each setting matters.
- Identity Server4 Sample Projects: The official sample repos include pre-configured MVC clients connected to IS4—you can clone these to see working examples and adapt them to your setup.
- 《Identity Server4 in Action》: This book offers deep dives into real-world scenarios, including integrating custom identity providers and troubleshooting common issues.
内容的提问来源于stack exchange,提问作者Roshan

