能否重新配置mod_auth_openidc令牌撤销请求中的aud声明?
解决mod_auth_openidc撤销请求aud声明不匹配问题
问题背景
应用通过引导用户到mod_auth_openidc的OIDCRedirectURI触发OIDC登出流程时,mod_auth_openidc会向OIDC提供商(OP)发送访问令牌撤销请求,但OP以请求中的aud声明与revocation_endpoint URI不匹配为由拒绝请求。
具体表现:
- OP的openid-configuration中,
token_endpoint与revocation_endpoint地址不同:"token_endpoint":"https://example.com/op/profile/oidc/token", "revocation_endpoint":"https://example.com/op/profile/oauth2/revocation" - 当mod_auth_openidc配置
OIDCProviderTokenEndpointAuth=client_secret_jwt时,撤销请求的JWT断言中aud字段被设置为token_endpoint地址:
但该断言被POST到revocation_endpoint,导致OP校验不通过。"aud": "https://example.com/op/profile/oidc/token"
代码追踪显示:oidc_logout_revoke_tokens函数通过oidc_cfg_provider_token_endpoint_url_get(provider)获取地址填充oidc_proto_profile_token_endpoint_auth_aud,复用了token_endpoint作为aud值。
解决方案
1. 自定义代码补丁(彻底解决)
直接修改mod_auth_openidc的代码逻辑,让撤销请求使用revocation_endpoint作为aud:
- 打开
logout.c文件,找到oidc_logout_revoke_tokens函数 - 将获取aud的代码从
oidc_cfg_provider_token_endpoint_url_get(provider)替换为oidc_cfg_provider_revocation_endpoint_url_get(provider) - 同步调整
profile.c中处理revocation请求的对应逻辑,确保aud值与目标端点一致 - 重新编译并部署修改后的mod_auth_openidc模块
2. OP端配置调整(临时规避)
如果无法自定义编译模块,可联系OP管理员:
- 将token_endpoint的地址添加到revocation_endpoint的允许aud列表中
- 让OP接受以token_endpoint为aud的撤销请求,绕过aud校验不匹配的问题
注意事项
- 代码补丁方式需关注后续mod_auth_openidc版本更新,避免自定义修改被覆盖
- 优先选择OP端配置调整,这是更轻量、无需修改模块的解决方案
内容的提问来源于stack exchange,提问作者lotic
相关产品推荐
相关产品推荐

