如何在Swagger UI向IdentityServer8认证时传递自定义参数?
问题描述
我正在使用Swagger UI测试需通过OAuth 2.0隐式流向IdentityServer8进行认证的API。请问是否有办法在认证过程中从Swagger UI向IdentityServer8传递自定义参数?支持自由文本输入框,或是选择服务器返回值的下拉列表?
相关截图:
目前想到一种不太规范的方法是将其嵌入客户端ID,但实现难度较大,希望有更优的解决方案!
解决方案
方案1:通过Swagger配置添加自由文本输入参数(快速实现)
如果是基于ASP.NET Core的Swashbuckle,可以直接在SwaggerGen配置中给OAuth2隐式流添加自定义查询参数,Swagger UI会自动生成对应的输入框:
services.AddSwaggerGen(c => { c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme { Type = SecuritySchemeType.OAuth2, Flows = new OpenApiOAuthFlows { Implicit = new OpenApiOAuthFlow { AuthorizationUrl = new Uri("https://你的IdentityServer8地址/connect/authorize"), Scopes = new Dictionary<string, string> { { "api_scope", "API访问权限" } }, // 配置自定义参数 AdditionalQueryParameters = new Dictionary<string, OpenApiParameter> { { "custom_param", new OpenApiParameter { Name = "custom_param", In = ParameterLocation.Query, Required = false, Schema = new OpenApiSchema { Type = "string" }, Description = "自定义业务参数" } } } } } }); });
配置完成后,Swagger UI的授权弹窗会出现custom_param的输入框,用户输入的值会自动作为查询参数携带到IdentityServer8的授权请求中。
方案2:自定义Swagger UI授权弹窗(支持下拉列表)
如果需要下拉列表这类复杂UI,需要修改Swagger UI的授权模板:
- 找到Swagger UI的
oauth2-authorize.html模板(ASP.NET Core项目通常在wwwroot/swagger目录下) - 在模板中添加自定义下拉列表:
<div class="form-group"> <label for="custom_select">自定义下拉参数</label> <select id="custom_select" name="custom_select"> <option value="option_a">选项A</option> <option value="option_b">选项B</option> </select> </div>
- 通过JS监听提交事件,将下拉值追加到授权URL:
const ui = SwaggerUIBundle({ url: "/swagger/v1/swagger.json", dom_id: '#swagger-ui', presets: [SwaggerUIBundle.presets.apis, SwaggerUIStandalonePreset], oauth2RedirectUrl: "https://你的Swagger地址/oauth2-redirect.html" }); // 监听授权表单提交 document.querySelector('.swagger-ui__oauth2-authorize-form').addEventListener('submit', (e) => { const selectValue = document.getElementById('custom_select').value; const authorizeUrl = new URL(ui.getConfigs().oauth2.authorizationUrl); authorizeUrl.searchParams.append('custom_select', selectValue); // 替换原授权URL(需根据Swagger UI版本调整具体实现) document.querySelector('.swagger-ui__oauth2-authorize-form [action]').setAttribute('action', authorizeUrl.toString()); });
方案3:利用标准acr_values参数(推荐规范方式)
如果自定义参数用于身份验证上下文控制,可以使用OAuth2标准的acr_values参数,IdentityServer8原生支持该参数传递自定义身份验证规则:
// 在Swashbuckle中配置 AdditionalQueryParameters = new Dictionary<string, OpenApiParameter> { { "acr_values", new OpenApiParameter { Name = "acr_values", In = ParameterLocation.Query, Required = false, Schema = new OpenApiSchema { Type = "string" }, Description = "身份验证上下文参数,格式示例:tenant:xxx" } } }
在IdentityServer8中,可通过IIdentityServerInteractionService获取该参数值,实现自定义业务逻辑。
内容的提问来源于stack exchange,提问作者EM0
相关产品推荐
相关产品推荐

