Bearer error="invalid_token", error_description="发行人无效"

w00*_*977 13 c# postman .net-core asp.net-core identityserver4

我有一个简单的 Web api 项目,如下所示:

[Authorize]
        [Route("Get")]
        public ActionResult<string> SayHello()
        {
            return "Hello World";
        }
Run Code Online (Sandbox Code Playgroud)

我正在尝试用邮递员测试它。按照此处的步骤操作:https://kevinchalet.com/2016/07/13/creating-your-own-openid-connect-server-with-asos-testing-your-authorization-server-with-postman/

1) 发送以下请求并按预期接收令牌:

在此输入图像描述

2) 尝试使用授权令牌发送另一个请求,如下所示:

在此输入图像描述

为什么我会收到 401(未经授权)错误?WWW-Authenticate 响应标头显示:Bearer error="invalid_token", error_description="The Issuer is invalid"。我正在使用.Net Core 3.1。我已经把截图中的敏感信息注释掉了。

从 MVC 应用程序访问时,Web api 按预期工作。

这是启动代码:

services.AddAuthentication("Bearer")
                .AddIdentityServerAuthentication(options =>
                {
                    options.Authority = identityUrl; //identityurl is a config item
                    options.RequireHttpsMetadata = false;
                    options.ApiName = apiName;

                });
Run Code Online (Sandbox Code Playgroud)

ned*_*179 8

我遇到了类似的问题。在发送请求并使用外部 IP 访问在 kubernetes 集群内运行的 Keycloak 实例时,我通过 Postman 生成令牌。当集群内的服务尝试根据权限验证令牌时,它失败了,因为它用于验证令牌的内部服务名称 (http://keycloak) 与 Postman 用于生成令牌的名称不同 (<external- keycloak-ip)。

由于这只是为了测试,我将其设置ValidateIssuer为 false。

options.TokenValidationParameters = new TokenValidationParameters
{
    ValidateIssuer = false 
};
Run Code Online (Sandbox Code Playgroud)


Joh*_*rth 5

我在 dotnet 5.0 上,将 swagger (NSwag.AspNetCore) 添加到我的 AzureAD“受保护”Web api,并收到有关无效颁发者的类似错误:

 date: Tue,16 Mar 2021 22:50:58 GMT 
 server: Microsoft-IIS/10.0 
 www-authenticate: Bearer error="invalid_token",error_description="The issuer 'https://sts.windows.net/<your-tenant-id>/' is invalid" 
 x-powered-by: ASP.NET 
Run Code Online (Sandbox Code Playgroud)

因此,我没有不验证发行人,而是将 sts.windows.net 添加到列表中(最后是重要部分):

// Enable JWT Bearer Authentication
services.AddAuthentication(sharedOptions =>
{
    sharedOptions.DefaultScheme = JwtBearerDefaults.AuthenticationScheme;
}).AddJwtBearer(options =>
{
    Configuration.Bind("AzureAd", options);
    // Authority will be Your AzureAd Instance and Tenant Id
    options.Authority = $"{Configuration["AzureAd:Instance"]}{Configuration["AzureAd:TenantId"]}/v2.0";

    // The valid audiences are both the Client ID(options.Audience) and api://{ClientID}
    options.TokenValidationParameters.ValidAudiences = new[]
    {
        Configuration["AzureAd:ClientId"], $"api://{Configuration["AzureAd:ClientId"]}",

    };
    // Valid issuers here:
    options.TokenValidationParameters.ValidIssuers = new[]
    {
        $"https://sts.windows.net/{Configuration["AzureAd:TenantId"]}/",
        $"{Configuration["AzureAd:Instance"]}{Configuration["AzureAd:TenantId"]}/"
    };
});
Run Code Online (Sandbox Code Playgroud)

这解决了我的问题。现在,我不知道为什么 NSwag 使用 sts.windows.net 作为令牌发行者。看来是错误的。我正在使用这些软件包版本:

    <PackageReference Include="Microsoft.AspNetCore.Authentication" Version="2.2.0" />
    <PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="5.0.3" />
    <PackageReference Include="NSwag.AspNetCore" Version="13.10.8" />
Run Code Online (Sandbox Code Playgroud)


Nan*_* Yu 4

中间件Authority的AddIdentityServerAuthentication应该是您的身份服务器的基地址,中间件将联系身份服务器的 OIDC 元数据端点以获取公钥以验证 JWT 令牌。

请确认 Authority 是您颁发 jwt 令牌的身份服务器的 url。