什么时候ProfileDataRequestContext.RequestedClaimTypes不为空?

dst*_*str 5 identityserver4

我尝试IdentityServer4示范项目,我添加用户声称ProfileDataRequestContext.IssuedClaims在IProfileService执行.我注意到的一件事是有一个context.RequestedClaimTypes集合,在我试过的任何资源/身份/范围配置变体中总是空的.在什么条件下这个集合有数据?

Mas*_*ton 12

如果在ApiResources你定义的定义中UserClaims,那么这些将被填充context.RequestClaimTypes.例如:

new ApiResource
{
  Name = "TestAPI",
  ApiSecrets = { new Secret("secret".Sha256()) },
  UserClaims = {
    JwtClaimTypes.Email,
    JwtClaimTypes.EmailVerified,
    JwtClaimTypes.PhoneNumber,
    JwtClaimTypes.PhoneNumberVerified,
    JwtClaimTypes.GivenName,
    JwtClaimTypes.FamilyName,
    JwtClaimTypes.PreferredUserName
                    },
  Description = "Test API",
  DisplayName = "Test API",
  Enabled = true,
  Scopes = { new Scope("testApiScore) }
}
Run Code Online (Sandbox Code Playgroud)

然后,您ProfileDataRequestContext.RequestClaimTypes将包含这些请求声明,以便您的Identity Server满足您认为合适的要求.


dst*_*str 0

答案: https: //github.com/IdentityServer/IdentityServer4/issues/1067

每当您请求具有关联声明的范围时。