无法重定向到结束会话端点,配置可能会丢失或OpenIdConnect SignOutAsync无效

时间:2018-04-13 11:28:53

标签: c# asp.net-core asp.net-core-2.0 openid-connect

我收到错误

  

无法重定向到结束会话端点,配置可能是   退出时丢失或无效。

当我处理退出时

public async Task LogOut()
{
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);            
    await HttpContext.SignOutAsync("oidc");
}

架构

services.AddAuthentication(sharedOptions =>
    {
        sharedOptions.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        sharedOptions.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        sharedOptions.DefaultSignOutScheme = "oidc";
        sharedOptions.DefaultChallengeScheme = "oidc";
    })
    .AddCookie(options =>
    {
        options.AccessDeniedPath = new PathString("/Access/Unauthorised");
        options.Cookie.Name = "MyCookie";
    })
    .AddOpenIdConnect("oidc", options =>
    {
        options.ClientId = Configuration["oidc:ClientId"];
        options.ClientSecret = Configuration["oidc:ClientSecret"]; // for code flow
        options.SignedOutRedirectUri = Configuration["oidc:SignedOutRedirectUri"];
        options.Authority = Configuration["oidc:Authority"];
        options.ResponseType = OpenIdConnectResponseType.Code;
        options.GetClaimsFromUserInfoEndpoint = true;
        options.CallbackPath = new PathString("/oidc");
        options.Events = new OpenIdConnectEvents()
        {
            OnRedirectToIdentityProvider = context =>
            {
                context.ProtocolMessage.SetParameter("pfidpadapterid", Configuration["oidc:PingProtocolMessage"]);
                return Task.FromResult(0);
            }
        };
    });

2 个答案:

答案 0 :(得分:3)

您的授权服务器似乎不支持会话管理和动态注册。受支持时,发现响应包含end_session_endpoint。这与SignedOutRedirectUri不同,get additional parameters在用户从授权服务器上注销时用作最终重定向目标。

OnRedirectToIdentityProviderForSignOut事件提供了一个设置发行者地址的选项,在本例中为注销URI:

options.Events = new OpenIdConnectEvents()
{
    options.Events.OnRedirectToIdentityProviderForSignOut = context =>
    {
        context.ProtocolMessage.IssuerAddress =
            GetAbsoluteUri(Configuration["oidc:EndSessionEndpoint"], Configuration["oidc:Authority"]);
        return Task.CompletedTask;
    };
}

helper方法用于在配置中同时支持相对路径和绝对路径:

private string GetAbsoluteUri(string signoutUri, string authority)
{
    var signOutUri = new Uri(signoutUri, UriKind.RelativeOrAbsolute);
    var authorityUri = new Uri(authority, UriKind.Absolute);

    var uri = signOutUri.IsAbsoluteUri ? signOutUri : new Uri(authorityUri, signOutUri);
    return uri.AbsoluteUri;
}   

通过这种方式,授权服务器可以在查询字符串中enter image description here,例如可以使用重定向回您的应用程序。

答案 1 :(得分:0)

要修复此处理 OnRedirectToIdentityProviderForSignOut 事件并手动指定Logout端点:

options.Events = new OpenIdConnectEvents()
{
    OnRedirectToIdentityProvider = context =>
    {
        context.ProtocolMessage.SetParameter("pfidpadapterid", Configuration["oidc:PingProtocolMessage"]);
        return Task.FromResult(0);
    },
    // handle the logout redirection 
    OnRedirectToIdentityProviderForSignOut = context =>
    {
        var logoutUri = Configuration["oidc:SignedOutRedirectUri"];
        context.Response.Redirect(logoutUri);
        context.HandleResponse();

        return Task.CompletedTask;
    }
};