Identity Server 4 未向控制器返回错误描述

2023-12-31

我有一个 Identity server 4 项目,它遵循有关如何显示错误的文档

家庭控制器:

public class HomeController : Controller
{
    private readonly IIdentityServerInteractionService _interaction;

    public HomeController(IIdentityServerInteractionService interaction)
    {
        _interaction = interaction;
    }

    public IActionResult Index()
    {
        return View();
    }

    public async Task<IActionResult> Error(string errorId)
    {
        var vm = new ErrorViewModel();
        var message = await _interaction.GetErrorContextAsync(errorId);
        if (message != null)
            vm.Error = message;
        return View("Error", vm);
    }
}

身份服务器本身在日志中提供了一些有用的信息

fail: IdentityServer4.Validation.AuthorizeRequestValidator[0]
      Unknown client or not enabled: 3CCF1B2D-D064-4A1B-BFD4-57E0451575C7.apps.biz
{
        "SubjectId": "anonymous",
        "RequestedScopes": "",
        "Raw": {
          "client_id": "3CCF1B2D-D064-4A1B-BFD4-57E0451575C7.test.apps.biz",
          "redirect_uri": "http://localhost:4200/signin-oidc",
          "response_type": "id_token",
          "scope": "openid profile",
          "response_mode": "form_post",
          "nonce": "636589548258549622.YzMwMzRkNjAtYWU2Ni00ODlmLTg3ZWQtNmRmOThhYjcyN2JlZWFkYjk2MjEtNDAxNC00ZTQ1LWEzZTAtNTZmMWIyNDhkZjg1",
          "state": "CfDJ8FDPGFWZWNNOmnYDxcFlnVDZgaOG1kNakiXQF48y_4gnSxuIVAVQmMJ_4j9SUZz1TXGJDt4-8EKmoxLXuw3SZgyc5fy1ODzdS0Njd68T1W9dGxt8rFNrUF0njKk3XrSRTeJ45geS_uOL4w89OVupVq4UtHVbKxj3UMZLCn4W-BAXpXfo43KIT8RvxICMjbNtvPM1toEmMSlfdic6T6EZoxXpwim919xMLeQCY0S7QZdbc9DFfUfJkVYsLrofiBvQtZLfQjRQNp_7MiYFz_C4IQ7BAupErvZpcNvpBhQJWIt8BKlACVfKLHbvO6M0FKqa9A",
          "x-client-SKU": "ID_NET",
          "x-client-ver": "2.1.4.0"
        }
      }

and

 fail: IdentityServer4.Validation.AuthorizeRequestValidator[0]
  Invalid redirect_uri: http://localhost:4200/signin-oidc
{
        "ClientId": "testclient",
        "ClientName": "testclient",
        "AllowedRedirectUris": [
          "http://localhost:5002/signin-oidc"
        ],
        "SubjectId": "anonymous",
        "RequestedScopes": "",
        "Raw": {
          "client_id": "testclient",
          "redirect_uri": "http://localhost:4200/signin-oidc",
          "response_type": "code id_token",
          "scope": "openid profile",
          "response_mode": "form_post",
          "nonce": "636589567957415216.ZjYyZTU3MTEtZWRhZi00N2RhLWI1MjQtZThlZjk4NjY2NmJmZDQ4ZmUzNzQtMTI3MS00YTdiLTgzNDUtYThlMWU2NzcxMmM5",
          "state": "CfDJ8FDPGFWZWNNOmnYDxcFlnVByKSJA-wSjaBBIB2p-d1oUhuZNGBiD1gOFpnyxevmIKxNY1Hf15vlbpgLZoEVQ8O7UhyOpR1ANgUhhyl9nL4M63-2am7F1LJf9hwijkS0_WpxxJ-jYHlq4r99fS2tcaPFZjAG_UNjWYgTshD5Kps3czFvJOG04plaCn2zcKCX5AGgTVnxlG7__hi1ifn-xOipynq5nHBIasMT6doCmpjktAqx7AOK4C1D__YbVMkcRhC70qYFCfoSNhpUrROXZobP6GxYXd1y5EEbA_oXJjmePFdEL-MFQp0o5D_H_mXsU1g",
          "x-client-SKU": "ID_NET",
          "x-client-ver": "2.1.4.0"
        }
      }

但是,唯一的信息不会返回给我的控制器GetErrorContextAsync因此只能向用户显示错误名称。

错误的描述根本没有填写。

我如何获得至少填充的描述?

我正在寻找一种为这里的开发人员显示一些明智信息的方法。然而,每个错误都会返回 unauthorized_client,所以我无法告诉开发人员这是重定向 URI 与无效客户端 ID 的问题。

if (vm.Error.Error == "unauthorized_client") vm.Error.ErrorDescription = "Contact plugin developer.";

注意:重定向 URI 似乎确实返回描述。


这是设计的目的。您无法访问原因unathorized_client在你的控制器中。

您还可以检查来源以了解发生了什么。

//////////////////////////////////////////////////////////
// check for valid client
//////////////////////////////////////////////////////////
var client = await _clients.FindEnabledClientByIdAsync(request.ClientId);
if (client == null)
{
    LogError("Unknown client or not enabled", request.ClientId, request);
    return Invalid(request, OidcConstants.AuthorizeErrors.UnauthorizedClient);
}

https://github.com/IdentityServer/IdentityServer4/blob/dev/src/IdentityServer4/Validation/AuthorizeRequestValidator.cs#L150 https://github.com/IdentityServer/IdentityServer4/blob/dev/src/IdentityServer4/Validation/AuthorizeRequestValidator.cs#L150

本文内容由网友自发贡献,版权归原作者所有,本站不承担相应法律责任。如您发现有涉嫌抄袭侵权的内容,请联系:hwhale#tublm.com(使用前将#替换为@)

Identity Server 4 未向控制器返回错误描述 的相关文章

随机推荐