You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否重新配置mod_auth_openidc令牌撤销请求中的aud声明?

解决mod_auth_openidc撤销请求aud声明不匹配问题

问题背景

应用通过引导用户到mod_auth_openidc的OIDCRedirectURI触发OIDC登出流程时,mod_auth_openidc会向OIDC提供商(OP)发送访问令牌撤销请求,但OP以请求中的aud声明与revocation_endpoint URI不匹配为由拒绝请求。

具体表现:

  • OP的openid-configuration中,token_endpoint与revocation_endpoint地址不同:
    "token_endpoint":"https://example.com/op/profile/oidc/token",
    "revocation_endpoint":"https://example.com/op/profile/oauth2/revocation"
    
  • 当mod_auth_openidc配置OIDCProviderTokenEndpointAuth=client_secret_jwt时,撤销请求的JWT断言中aud字段被设置为token_endpoint地址:
    "aud": "https://example.com/op/profile/oidc/token"
    
    但该断言被POST到revocation_endpoint,导致OP校验不通过。

代码追踪显示:oidc_logout_revoke_tokens函数通过oidc_cfg_provider_token_endpoint_url_get(provider)获取地址填充oidc_proto_profile_token_endpoint_auth_aud,复用了token_endpoint作为aud值。

解决方案

1. 自定义代码补丁(彻底解决)

直接修改mod_auth_openidc的代码逻辑,让撤销请求使用revocation_endpoint作为aud:

  • 打开logout.c文件,找到oidc_logout_revoke_tokens函数
  • 将获取aud的代码从oidc_cfg_provider_token_endpoint_url_get(provider)替换为oidc_cfg_provider_revocation_endpoint_url_get(provider)
  • 同步调整profile.c中处理revocation请求的对应逻辑,确保aud值与目标端点一致
  • 重新编译并部署修改后的mod_auth_openidc模块

2. OP端配置调整(临时规避)

如果无法自定义编译模块,可联系OP管理员:

  • 将token_endpoint的地址添加到revocation_endpoint的允许aud列表中
  • 让OP接受以token_endpoint为aud的撤销请求,绕过aud校验不匹配的问题

注意事项

  • 代码补丁方式需关注后续mod_auth_openidc版本更新,避免自定义修改被覆盖
  • 优先选择OP端配置调整,这是更轻量、无需修改模块的解决方案

内容的提问来源于stack exchange,提问作者lotic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 07:13:11