
前文介绍了identity的用法,同时介绍了什么是identitySourece、apiSource、client 这几个概念,和具体案例,那么下面继续介绍案例了。



官网给的第二个例子是这个: https://identityserver4.readthedocs.io/en/latest/quickstarts/2_interactive_aspnetcore.html

首先来看下与identityServer 对接的客户端是怎么样的。


  1. JwtSecurityTokenHandler.DefaultMapInboundClaims = false;
  2. services.AddAuthentication(options =>
  3. {
  4. options.DefaultScheme = "Cookies";
  5. options.DefaultChallengeScheme = "oidc";
  6. })
  7. .AddCookie("Cookies")
  8. .AddOpenIdConnect("oidc", options =>
  9. {
  10. options.Authority = "https://localhost:5001";
  11. options.ClientId = "mvc";
  12. options.ClientSecret = "secret";
  13. options.ResponseType = "code";
  14. options.SaveTokens = true;
  15. });


AddCookie("Cookies") 就是注入cookies 方案,这个要和前面设置的options.DefaultScheme = "Cookies" 对应的,前面是配置,这个是具体实现。


然后下面AddOpenIdConnect 注册了查问访问oidc。

  1. public static AuthenticationBuilder AddOpenIdConnect(this AuthenticationBuilder builder, string authenticationScheme, string displayName, Action<OpenIdConnectOptions> configureOptions)
  2. {
  3. builder.Services.TryAddEnumerable(ServiceDescriptor.Singleton<IPostConfigureOptions<OpenIdConnectOptions>, OpenIdConnectPostConfigureOptions>());
  4. return builder.AddRemoteScheme<OpenIdConnectOptions, OpenIdConnectHandler>(authenticationScheme, displayName, configureOptions);
  5. }

这里再介绍一下DefaultScheme 和 DefaultChallengeScheme 分别是什么哈。

  1. /// <summary>
  2. /// Used as the fallback default scheme for all the other defaults.
  3. /// </summary>
  4. public string DefaultScheme { get; set; }


  1. /// <summary>
  2. /// Used as the default scheme by <see cref="IAuthenticationService.ChallengeAsync(HttpContext, string, AuthenticationProperties)"/>.
  3. /// </summary>
  4. public string DefaultChallengeScheme { get; set; }

这个就是IAuthenticationService.ChallengeAsync 会使用到这个。

  1. /// <summary>
  2. /// Challenge the specified authentication scheme.
  3. /// </summary>
  4. /// <param name="context">The <see cref="HttpContext"/>.</param>
  5. /// <param name="scheme">The name of the authentication scheme.</param>
  6. /// <param name="properties">The <see cref="AuthenticationProperties"/>.</param>
  7. /// <returns>A task.</returns>
  8. Task ChallengeAsync(HttpContext context, string scheme, AuthenticationProperties properties);


我们知道使用了AddAuthentication 是添加这个服务,我们需要在中间件中注册进去。

  1. app.UseRouting();
  2. app.UseAuthentication();
  3. app.UseAuthorization();

那么这里mvc 客户端就算完成了。

那么identityServer 怎么该做些什么呢?

  1. 肯定是要注册客户端的嘛
  1. new Client
  2. {
  3. ClientId = "mvc",
  4. ClientSecrets = { new Secret("secret".Sha256()) },
  5. AllowedGrantTypes = GrantTypes.Code,
  6. // where to redirect to after login
  7. RedirectUris = { "https://localhost:5002/signin-oidc" },
  8. // where to redirect to after logout
  9. PostLogoutRedirectUris = { "https://localhost:5002/signout-callback-oidc" },
  10. AllowedScopes = new List<string>
  11. {
  12. IdentityServerConstants.StandardScopes.OpenId,
  13. IdentityServerConstants.StandardScopes.Profile
  14. }
  15. }


RedirectUris 是登录完成之后会跳转的地址。

PostLogoutRedirectUris 是登录失败后会跳转的位置。


这里的流程是这样的,如果没有登录,那么就会跳转到identity Server的登录页面,然后再跳转回客户端的接收token 或者code 的路径,然后这个路径再跳转到一开始未登录的页面,有些直接到首页的。

然后可以看到这两个路径signin-oidc 和 signout-callback-oidc 发现我们mvc 中根本就没有写这两个路由,这个是由AddOpenIdConnect 提供的。

我们看下OpenIdConnectOptions 配置。

拦截到这两个路由,会进入OpenIdConnectHandler 做相应的处理。

这样子client 就注册了。

  1. 登录,一般模式是需要账户密码,那么要账户密码就需要用户,这个用户怎么注册进去呢?
  1. public static List<TestUser> Users
  2. {
  3. get
  4. {
  5. var address = new
  6. {
  7. street_address = "One Hacker Way",
  8. locality = "Heidelberg",
  9. postal_code = 69118,
  10. country = "Germany"
  11. };
  12. return new List<TestUser>
  13. {
  14. new TestUser
  15. {
  16. SubjectId = "818727",
  17. Username = "alice",
  18. Password = "alice",
  19. Claims =
  20. {
  21. new Claim(JwtClaimTypes.Name, "Alice Smith"),
  22. new Claim(JwtClaimTypes.GivenName, "Alice"),
  23. new Claim(JwtClaimTypes.FamilyName, "Smith"),
  24. new Claim(JwtClaimTypes.Email, "AliceSmith@email.com"),
  25. new Claim(JwtClaimTypes.EmailVerified, "true", ClaimValueTypes.Boolean),
  26. new Claim(JwtClaimTypes.WebSite, "http://alice.com"),
  27. new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)
  28. }
  29. },
  30. new TestUser
  31. {
  32. SubjectId = "88421113",
  33. Username = "bob",
  34. Password = "bob",
  35. Claims =
  36. {
  37. new Claim(JwtClaimTypes.Name, "Bob Smith"),
  38. new Claim(JwtClaimTypes.GivenName, "Bob"),
  39. new Claim(JwtClaimTypes.FamilyName, "Smith"),
  40. new Claim(JwtClaimTypes.Email, "BobSmith@email.com"),
  41. new Claim(JwtClaimTypes.EmailVerified, "true", ClaimValueTypes.Boolean),
  42. new Claim(JwtClaimTypes.WebSite, "http://bob.com"),
  43. new Claim(JwtClaimTypes.Address, JsonSerializer.Serialize(address), IdentityServerConstants.ClaimValueTypes.Json)
  44. }
  45. }
  46. };
  47. }
  48. }


  1. 这个时候还得处理identity Server的逻辑
  1. /// <summary>
  2. /// Entry point into the login workflow
  3. /// </summary>
  4. [HttpGet]
  5. public async Task<IActionResult> Login(string returnUrl)
  6. {
  7. // build a model so we know what to show on the login page
  8. var vm = await BuildLoginViewModelAsync(returnUrl);
  9. if (vm.IsExternalLoginOnly)
  10. {
  11. // we only have one option for logging in and it's an external provider
  12. return RedirectToAction("Challenge", "External", new { scheme = vm.ExternalLoginScheme, returnUrl });
  13. }
  14. return View(vm);
  15. }



这里跳转到5001 identity server 服务中去。


然后又转到了account login

然后我们看到account login 接收到了什么。

这里可以看到如果login action 结束会进入到/connect/authorize/callback。

/connect/authorize -> account/login -> /connect/authorize/callback, 中间account/login就是用来验证是否通过的。



  1. // check if we are in the context of an authorization request
  2. var context = await _interaction.GetAuthorizationContextAsync(model.ReturnUrl);
  3. // the user clicked the "cancel" button
  4. if (button != "login")
  5. {
  6. if (context != null)
  7. {
  8. // if the user cancels, send a result back into IdentityServer as if they
  9. // denied the consent (even if this client does not require consent).
  10. // this will send back an access denied OIDC error response to the client.
  11. await _interaction.DenyAuthorizationAsync(context, AuthorizationError.AccessDenied);
  12. // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null
  13. if (context.IsNativeClient())
  14. {
  15. // The client is native, so this change in how to
  16. // return the response is for better UX for the end user.
  17. return this.LoadingPage("Redirect", model.ReturnUrl);
  18. }
  19. return Redirect(model.ReturnUrl);
  20. }
  21. else
  22. {
  23. // since we don't have a valid context, then we just go back to the home page
  24. return Redirect("~/");
  25. }
  26. }



  1. if (ModelState.IsValid)
  2. {
  3. // validate username/password against in-memory store
  4. if (_users.ValidateCredentials(model.Username, model.Password))
  5. {
  6. var user = _users.FindByUsername(model.Username);
  7. await _events.RaiseAsync(new UserLoginSuccessEvent(user.Username, user.SubjectId, user.Username, clientId: context?.Client.ClientId));
  8. // only set explicit expiration here if user chooses "remember me".
  9. // otherwise we rely upon expiration configured in cookie middleware.
  10. AuthenticationProperties props = null;
  11. if (AccountOptions.AllowRememberLogin && model.RememberLogin)
  12. {
  13. props = new AuthenticationProperties
  14. {
  15. IsPersistent = true,
  16. ExpiresUtc = DateTimeOffset.UtcNow.Add(AccountOptions.RememberMeLoginDuration)
  17. };
  18. };
  19. // issue authentication cookie with subject ID and username
  20. var isuser = new IdentityServerUser(user.SubjectId)
  21. {
  22. DisplayName = user.Username
  23. };
  24. await HttpContext.SignInAsync(isuser, props);
  25. if (context != null)
  26. {
  27. if (context.IsNativeClient())
  28. {
  29. // The client is native, so this change in how to
  30. // return the response is for better UX for the end user.
  31. return this.LoadingPage("Redirect", model.ReturnUrl);
  32. }
  33. // we can trust model.ReturnUrl since GetAuthorizationContextAsync returned non-null
  34. return Redirect(model.ReturnUrl);
  35. }
  36. // request for a local page
  37. if (Url.IsLocalUrl(model.ReturnUrl))
  38. {
  39. return Redirect(model.ReturnUrl);
  40. }
  41. else if (string.IsNullOrEmpty(model.ReturnUrl))
  42. {
  43. return Redirect("~/");
  44. }
  45. else
  46. {
  47. // user might have clicked on a malicious link - should be logged
  48. throw new Exception("invalid return URL");
  49. }
  50. }
  51. }


await HttpContext.SignInAsync(isuser, props); 这个就是设置cookie了,很多人还不了解里面做了啥,看下源码。


然后看一下_inner.SignInasync 做了什么。

这里放下源码,然后这个innser 就是 AuthenticationService。

  1. public virtual async Task SignInAsync(HttpContext context, string scheme, ClaimsPrincipal principal, AuthenticationProperties properties)
  2. {
  3. if (principal == null)
  4. {
  5. throw new ArgumentNullException(nameof(principal));
  6. }
  7. if (Options.RequireAuthenticatedSignIn)
  8. {
  9. if (principal.Identity == null)
  10. {
  11. throw new InvalidOperationException("SignInAsync when principal.Identity == null is not allowed when AuthenticationOptions.RequireAuthenticatedSignIn is true.");
  12. }
  13. if (!principal.Identity.IsAuthenticated)
  14. {
  15. throw new InvalidOperationException("SignInAsync when principal.Identity.IsAuthenticated is false is not allowed when AuthenticationOptions.RequireAuthenticatedSignIn is true.");
  16. }
  17. }
  18. if (scheme == null)
  19. {
  20. var defaultScheme = await Schemes.GetDefaultSignInSchemeAsync();
  21. scheme = defaultScheme?.Name;
  22. if (scheme == null)
  23. {
  24. throw new InvalidOperationException($"No authenticationScheme was specified, and there was no DefaultSignInScheme found. The default schemes can be set using either AddAuthentication(string defaultScheme) or AddAuthentication(Action<AuthenticationOptions> configureOptions).");
  25. }
  26. }
  27. var handler = await Handlers.GetHandlerAsync(context, scheme);
  28. if (handler == null)
  29. {
  30. throw await CreateMissingSignInHandlerException(scheme);
  31. }
  32. var signInHandler = handler as IAuthenticationSignInHandler;
  33. if (signInHandler == null)
  34. {
  35. throw await CreateMismatchedSignInHandlerException(scheme, handler);
  36. }
  37. await signInHandler.SignInAsync(principal, properties);
  38. }






  1. public IActionResult Logout()
  2. {
  3. return SignOut("Cookies", "oidc");
  4. }


这个肯定是清除了cookie,并通知了identity server 进行清除cookie。

  1. public virtual SignOutResult SignOut(params string[] authenticationSchemes)
  2. => new SignOutResult(authenticationSchemes);
  3. public SignOutResult(IList<string> authenticationSchemes)
  4. : this(authenticationSchemes, properties: null)
  5. {
  6. }

SignOutResult : ActionResult 是一个actionResult,那么actionResult 会做什么呢?

  1. An <see cref="ActionResult"/> that on execution invokes <see cref="M:HttpContext.SignOutAsync"/>.

那么SignOutResult 其会执行下面这一段。

  1. public override async Task ExecuteResultAsync(ActionContext context)
  2. {
  3. if (context == null)
  4. {
  5. throw new ArgumentNullException(nameof(context));
  6. }
  7. if (AuthenticationSchemes == null)
  8. {
  9. throw new InvalidOperationException(
  10. Resources.FormatPropertyOfTypeCannotBeNull(
  11. /* property: */ nameof(AuthenticationSchemes),
  12. /* type: */ nameof(SignOutResult)));
  13. }
  14. var loggerFactory = context.HttpContext.RequestServices.GetRequiredService<ILoggerFactory>();
  15. var logger = loggerFactory.CreateLogger<SignOutResult>();
  16. logger.SignOutResultExecuting(AuthenticationSchemes);
  17. if (AuthenticationSchemes.Count == 0)
  18. {
  19. await context.HttpContext.SignOutAsync(Properties);
  20. }
  21. else
  22. {
  23. for (var i = 0; i < AuthenticationSchemes.Count; i++)
  24. {
  25. await context.HttpContext.SignOutAsync(AuthenticationSchemes[i], Properties);
  26. }
  27. }
  28. }

重点看context.HttpContext.SignOutAsync 做了什么。AuthenticationSchemes 我们传递了SignOut("Cookies", "oidc")。

  1. public static Task SignOutAsync(this HttpContext context, string scheme, AuthenticationProperties properties) =>
  2. context.RequestServices.GetRequiredService<IAuthenticationService>().SignOutAsync(context, scheme, properties);


那么IAuthenticationService 注入的是什么呢?


  1. public virtual async Task SignOutAsync(HttpContext context, string scheme, AuthenticationProperties properties)
  2. {
  3. if (scheme == null)
  4. {
  5. var defaultScheme = await Schemes.GetDefaultSignOutSchemeAsync();
  6. scheme = defaultScheme?.Name;
  7. if (scheme == null)
  8. {
  9. throw new InvalidOperationException($"No authenticationScheme was specified, and there was no DefaultSignOutScheme found. The default schemes can be set using either AddAuthentication(string defaultScheme) or AddAuthentication(Action<AuthenticationOptions> configureOptions).");
  10. }
  11. }
  12. var handler = await Handlers.GetHandlerAsync(context, scheme);
  13. if (handler == null)
  14. {
  15. throw await CreateMissingSignOutHandlerException(scheme);
  16. }
  17. var signOutHandler = handler as IAuthenticationSignOutHandler;
  18. if (signOutHandler == null)
  19. {
  20. throw await CreateMismatchedSignOutHandlerException(scheme, handler);
  21. }
  22. await signOutHandler.SignOutAsync(properties);
  23. }

那么其实就是分为两步,一步是清除自身的cookie,自身退出登录,然后通知identityserver 退出登录(清除cookie)

cookie 自身的就不看了,看identity相关处理逻辑。

  1. public async virtual Task SignOutAsync(AuthenticationProperties properties)
  2. {
  3. var target = ResolveTarget(Options.ForwardSignOut);
  4. if (target != null)
  5. {
  6. await Context.SignOutAsync(target, properties);
  7. return;
  8. }
  9. properties = properties ?? new AuthenticationProperties();
  10. Logger.EnteringOpenIdAuthenticationHandlerHandleSignOutAsync(GetType().FullName);
  11. if (_configuration == null && Options.ConfigurationManager != null)
  12. {
  13. _configuration = await Options.ConfigurationManager.GetConfigurationAsync(Context.RequestAborted);
  14. }
  15. var message = new OpenIdConnectMessage()
  16. {
  17. EnableTelemetryParameters = !Options.DisableTelemetry,
  18. IssuerAddress = _configuration?.EndSessionEndpoint ?? string.Empty,
  19. // Redirect back to SigneOutCallbackPath first before user agent is redirected to actual post logout redirect uri
  20. PostLogoutRedirectUri = BuildRedirectUriIfRelative(Options.SignedOutCallbackPath)
  21. };
  22. // Get the post redirect URI.
  23. if (string.IsNullOrEmpty(properties.RedirectUri))
  24. {
  25. properties.RedirectUri = BuildRedirectUriIfRelative(Options.SignedOutRedirectUri);
  26. if (string.IsNullOrWhiteSpace(properties.RedirectUri))
  27. {
  28. properties.RedirectUri = OriginalPathBase + OriginalPath + Request.QueryString;
  29. }
  30. }
  31. Logger.PostSignOutRedirect(properties.RedirectUri);
  32. // Attach the identity token to the logout request when possible.
  33. message.IdTokenHint = await Context.GetTokenAsync(Options.SignOutScheme, OpenIdConnectParameterNames.IdToken);
  34. var redirectContext = new RedirectContext(Context, Scheme, Options, properties)
  35. {
  36. ProtocolMessage = message
  37. };
  38. await Events.RedirectToIdentityProviderForSignOut(redirectContext);
  39. if (redirectContext.Handled)
  40. {
  41. Logger.RedirectToIdentityProviderForSignOutHandledResponse();
  42. return;
  43. }
  44. message = redirectContext.ProtocolMessage;
  45. if (!string.IsNullOrEmpty(message.State))
  46. {
  47. properties.Items[OpenIdConnectDefaults.UserstatePropertiesKey] = message.State;
  48. }
  49. message.State = Options.StateDataFormat.Protect(properties);
  50. if (string.IsNullOrEmpty(message.IssuerAddress))
  51. {
  52. throw new InvalidOperationException("Cannot redirect to the end session endpoint, the configuration may be missing or invalid.");
  53. }
  54. if (Options.AuthenticationMethod == OpenIdConnectRedirectBehavior.RedirectGet)
  55. {
  56. var redirectUri = message.CreateLogoutRequestUrl();
  57. if (!Uri.IsWellFormedUriString(redirectUri, UriKind.Absolute))
  58. {
  59. Logger.InvalidLogoutQueryStringRedirectUrl(redirectUri);
  60. }
  61. Response.Redirect(redirectUri);
  62. }
  63. else if (Options.AuthenticationMethod == OpenIdConnectRedirectBehavior.FormPost)
  64. {
  65. var content = message.BuildFormPost();
  66. var buffer = Encoding.UTF8.GetBytes(content);
  67. Response.ContentLength = buffer.Length;
  68. Response.ContentType = "text/html;charset=UTF-8";
  69. // Emit Cache-Control=no-cache to prevent client caching.
  70. Response.Headers[HeaderNames.CacheControl] = "no-cache, no-store";
  71. Response.Headers[HeaderNames.Pragma] = "no-cache";
  72. Response.Headers[HeaderNames.Expires] = HeaderValueEpocDate;
  73. await Response.Body.WriteAsync(buffer, 0, buffer.Length);
  74. }
  75. else
  76. {
  77. throw new NotImplementedException($"An unsupported authentication method has been configured: {Options.AuthenticationMethod}");
  78. }
  79. Logger.AuthenticationSchemeSignedOut(Scheme.Name);
  80. }

会发送请求,然后调用identity 登出通知。


  1. 调用自身的logout

  1. 调用identityserver 封装的logout。

  1. 调用identityserver 自己封装的logout

  1. 调用identityserver 封装的logout 回调

  1. 客户可以回调回去。





然后我们可以选择登出的方式有get 和post,post的情况下是这样的。



