use*_*702 7 thinktecture-ident-server identityserver3 identityserver4
我正在为我的一个Identity Server 3客户端使用授权代码流,它配置如下:
ClientId = "tripgalleryauthcode",
ClientName = "Trip Gallery",
Flow = Flows.AuthorizationCode,
AllowAccessToAllScopes = true,
RequireConsent = false,
// redirect = URI of our callback controller in the IOS application
RedirectUris = new List<string>
{
"somecallbackuri"
},
ClientSecrets = new List<Secret>()
{
"somesecret"
},
// refresh token options
AccessTokenType = AccessTokenType.Jwt,
AccessTokenLifetime = 120,
RefreshTokenUsage = TokenUsage.OneTimeOnly,
RefreshTokenExpiration = TokenExpiration.Absolute,
AbsoluteRefreshTokenLifetime = 360,
Run Code Online (Sandbox Code Playgroud)
如您所见,它被配置为在2分钟内使访问令牌到期,在6分钟内使刷新令牌到期.我这样做是因为我想尝试在更短的时间范围内调试问题而不是我在生产中使用的那个:刷新令牌15天,访问令牌1小时.我们注意到由于某种原因,今天发布的刷新令牌明天不起作用.这就是为什么我决定减少时间,这就是发生的事情:
我注意到了更多.发生的事情是访问令牌到期后2分钟我得到400错误.它说刷新令牌无效.
这是Identity Server的日志.
w3wp.exe Information: 0 : 2016-11-23 10:56:15.802 +00:00 [Information] Start token request
w3wp.exe Information: 0 : 2016-11-23 10:56:15.802 +00:00 [Information] Client secret id found: "tripgalleryauthcode"
w3wp.exe Information: 0 : 2016-11-23 10:56:15.802 +00:00 [Information] Client validation success
w3wp.exe Information: 0 : 2016-11-23 10:56:15.802 +00:00 [Information] Start token request validation
w3wp.exe Information: 0 : 2016-11-23 10:56:15.802 +00:00 [Information] Start validation of refresh token request
w3wp.exe Warning: 0 : 2016-11-23 10:56:15.802 +00:00 [Warning] "Refresh token has expired"
"{
\"ClientId\": \"tripgalleryauthcode\",
\"ClientName\": \"Trip Gallery\",
\"GrantType\": \"refresh_token\",
\"RefreshToken\": \"d12f50289e5cded13082de989a64ac01\",
\"Raw\": {
\"grant_type\": \"refresh_token\",
\"refresh_token\": \"d12f50289e5cded13082de989a64ac01\"
}
}"
w3wp.exe Information: 0 : 2016-11-23 10:56:15.818 +00:00 [Information] End token request
w3wp.exe Information: 0 : 2016-11-23 10:56:15.818 +00:00 [Information] Returning error: invalid_grant
Run Code Online (Sandbox Code Playgroud)
我真的很想知道导致该行为的原因以及导致我的到期令牌在截止日期之前到期的原因.
发生这种情况的原因是 JWT 内置了时钟偏差功能,可以保护您免受时钟不同步的影响。如果没有这个,您可能会遇到令牌尚未生效的问题。
默认值为 5 分钟 - 这会影响access_token以及refresh_token.
您可以使用JwtBearerOptions.TokenValidationParameters.ClockSkew,更改此值IdentityServer4.AccessTokenValidation.CombinedAuthenticationOptions
官方 JWT 草案中也指定了此行为:
实施者可以提供一些小的余地,通常不超过几分钟,以解决时钟偏差。它的值必须是包含 IntDate 值的数字。此声明是可选的。
| 归档时间: |
|
| 查看次数: |
1373 次 |
| 最近记录: |