You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Swagger UI向IdentityServer8认证时传递自定义参数?

问题描述

我正在使用Swagger UI测试需通过OAuth 2.0隐式流向IdentityServer8进行认证的API。请问是否有办法在认证过程中从Swagger UI向IdentityServer8传递自定义参数?支持自由文本输入框,或是选择服务器返回值的下拉列表?

相关截图:
Swagger authorization

目前想到一种不太规范的方法是将其嵌入客户端ID,但实现难度较大,希望有更优的解决方案!


解决方案

方案1:通过Swagger配置添加自由文本输入参数(快速实现)

如果是基于ASP.NET Core的Swashbuckle,可以直接在SwaggerGen配置中给OAuth2隐式流添加自定义查询参数,Swagger UI会自动生成对应的输入框:

services.AddSwaggerGen(c =>
{
    c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme
    {
        Type = SecuritySchemeType.OAuth2,
        Flows = new OpenApiOAuthFlows
        {
            Implicit = new OpenApiOAuthFlow
            {
                AuthorizationUrl = new Uri("https://你的IdentityServer8地址/connect/authorize"),
                Scopes = new Dictionary<string, string> { { "api_scope", "API访问权限" } },
                // 配置自定义参数
                AdditionalQueryParameters = new Dictionary<string, OpenApiParameter>
                {
                    { "custom_param", new OpenApiParameter
                        {
                            Name = "custom_param",
                            In = ParameterLocation.Query,
                            Required = false,
                            Schema = new OpenApiSchema { Type = "string" },
                            Description = "自定义业务参数"
                        }
                    }
                }
            }
        }
    });
});

配置完成后,Swagger UI的授权弹窗会出现custom_param的输入框,用户输入的值会自动作为查询参数携带到IdentityServer8的授权请求中。

方案2:自定义Swagger UI授权弹窗(支持下拉列表)

如果需要下拉列表这类复杂UI,需要修改Swagger UI的授权模板:

  1. 找到Swagger UI的oauth2-authorize.html模板(ASP.NET Core项目通常在wwwroot/swagger目录下)
  2. 在模板中添加自定义下拉列表:
<div class="form-group">
  <label for="custom_select">自定义下拉参数</label>
  <select id="custom_select" name="custom_select">
    <option value="option_a">选项A</option>
    <option value="option_b">选项B</option>
  </select>
</div>
  1. 通过JS监听提交事件,将下拉值追加到授权URL:
const ui = SwaggerUIBundle({
  url: "/swagger/v1/swagger.json",
  dom_id: '#swagger-ui',
  presets: [SwaggerUIBundle.presets.apis, SwaggerUIStandalonePreset],
  oauth2RedirectUrl: "https://你的Swagger地址/oauth2-redirect.html"
});

// 监听授权表单提交
document.querySelector('.swagger-ui__oauth2-authorize-form').addEventListener('submit', (e) => {
  const selectValue = document.getElementById('custom_select').value;
  const authorizeUrl = new URL(ui.getConfigs().oauth2.authorizationUrl);
  authorizeUrl.searchParams.append('custom_select', selectValue);
  // 替换原授权URL(需根据Swagger UI版本调整具体实现)
  document.querySelector('.swagger-ui__oauth2-authorize-form [action]').setAttribute('action', authorizeUrl.toString());
});

方案3:利用标准acr_values参数(推荐规范方式)

如果自定义参数用于身份验证上下文控制,可以使用OAuth2标准的acr_values参数,IdentityServer8原生支持该参数传递自定义身份验证规则:

// 在Swashbuckle中配置
AdditionalQueryParameters = new Dictionary<string, OpenApiParameter>
{
    { "acr_values", new OpenApiParameter
        {
            Name = "acr_values",
            In = ParameterLocation.Query,
            Required = false,
            Schema = new OpenApiSchema { Type = "string" },
            Description = "身份验证上下文参数,格式示例:tenant:xxx"
        }
    }
}

在IdentityServer8中,可通过IIdentityServerInteractionService获取该参数值,实现自定义业务逻辑。


内容的提问来源于stack exchange,提问作者EM0

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 03:57:06