Identityserver Usermanagement

作者 DuendeSoftwarefb32edc51982无许可证9 个星标收录于 2026年10月8日更新于 2026年10月8日仓库4周前更新

Setting up Duende User Management with IdentityServer: passwordless authentication (OTP, TOTP, passkeys), storage configuration, user lifecycle, and migration from ASP.NET Identity.

AI 生成的概览

指导在 IdentityServer 中设置 Duende 用户管理,涵盖无密码认证、存储、用户生命周期与迁移。

功能
该技能提供将 Duende 用户管理添加到 Duende IdentityServer 项目的说明。内容涵盖包安装、Program.cs 配置、OTP 分发器、认证方式、存储提供程序、声明映射、用户生命周期以及从 ASP.NET Identity 迁移。它还列出了反模式和常见陷阱。
适用场景
适用于向 Duende IdentityServer 项目添加用户管理、设置无密码认证、配置存储提供程序或从 ASP.NET Identity 迁移用户时。
运行要求
需要 .NET 10 SDK 或更高版本,以及 Duende.IdentityServer、Duende.UserManagement.IdentityServer8 和某个 Duende.Storage 包(SQLite、PostgreSQL 或 SQL Server)。生产环境 OTP 发送需要 SMTP 凭据。不包含脚本,仅为说明文档。

User Management

When to Use This Skill

  • Adding user management to a Duende IdentityServer project
  • Setting up passwordless authentication (OTP, TOTP, passkeys)
  • Configuring storage providers (PostgreSQL, SQL Server, SQLite)
  • Integrating User Management with IdentityServer for claims and login/logout
  • Managing user profiles, roles, and groups
  • Migrating users from ASP.NET Identity

Core Principles

  • Duende User Management is passwordless-first — OTP email/SMS is the default flow
  • Requires Duende.UserManagement.IdentityServer8 NuGet package + .NET 10
  • Storage is document-based (no EF migrations needed) — schema auto-creates at startup
  • Configuration goes inside AddUserManagement(), not at top level
  • Use app.UseIdentityServer() (not UseAuthentication() separately)

Docs: https://docs.duendesoftware.com/identityserver/usermanagement

Setup

1. Add Packages

bash
dotnet add package Duende.IdentityServerdotnet add package Duende.UserManagement.IdentityServer8dotnet add package Duende.Storage.Sqlite  # or .PostgreSQL, .Mssql

2. Configure Program.cs

csharp
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddIdentityServer(options =>{    options.UserInteraction.LoginUrl = "/Account/Login";    options.UserInteraction.LogoutUrl = "/Account/Logout";})    .AddInMemoryClients(Config.Clients)    .AddInMemoryIdentityResources(Config.IdentityResources)    .AddUserManagement(options =>    {        // Storage (pick one)        options.AddSqliteStore("Data Source=users.db");        // options.AddPostgreSqlStore(connectionString);        // options.AddSqlServerStore(connectionString);
        // OTP delivery        options.UseSmtpOtpDispatcher(smtp =>            builder.Configuration.GetSection("Smtp").Bind(smtp));    });
var app = builder.Build();
// Auto-create database schemavar schema = app.Services.GetRequiredService<IDatabaseSchema>();await schema.CreateIfNotExistsAsync();
app.UseIdentityServer();app.MapRazorPages();app.Run();

3. OTP Dispatcher

Console (development):

csharp
builder.Services.AddSingleton<IOtpDispatcher, ConsoleOtpDispatcher>();

SMTP (production):

csharp
options.UseSmtpOtpDispatcher(x =>{    x.Host = "smtp.example.com";    x.Port = 587;    x.Username = "[email protected]";    x.Password = "secret";    x.FromAddress = "[email protected]";});

Authentication Methods

MethodDescriptionSetup
OTP (default)One-time codes via email/SMSIOtpDispatcher implementation
TOTPAuthenticator apps (RFC 6238)Built-in, user enrollment required
PasskeysWebAuthn/FIDO2 phishing-resistantBuilt-in, browser support required
PasswordsTraditional username/password (PBKDF2)Opt-in, not recommended as primary
ExternalOAuth 2.0 / OIDC federated loginStandard ASP.NET Core auth handlers
Recovery codesSingle-use backup codesAuto-generated during 2FA setup

IdentityServer Integration

AddUserManagement() is called on the IdentityServer builder — it automatically:

  • Registers IProfileService for claims delivery
  • Handles login/logout flows
  • Maps user attributes to identity token claims

Claims Mapping

User profile attributes are mapped to claims based on requested scopes:

  • openid → sub
  • profile → name, given_name, family_name, etc.
  • email → email, email_verified

Custom attributes are available through custom identity resources.

Storage

ProviderPackageConnection
SQLiteDuende.Storage.SqliteData Source=users.db
PostgreSQLDuende.Storage.PostgreSQLStandard connection string
SQL ServerDuende.Storage.MssqlStandard connection string
In-Memory(built-in)Data Source=:memory: (testing only)

Storage is document-based — no EF Core migrations needed. Call IDatabaseSchema.CreateIfNotExistsAsync() at startup to ensure schema exists.

User Lifecycle

  • Creation: Users are created on first authentication (passwordless) or via admin APIs
  • Profiles: Custom attributes stored as key-value pairs, organized in attribute groups
  • Roles & Groups: RBAC support with group membership and role inheritance
  • Deletion: Full user deletion with cascade

Migration from ASP.NET Identity

csharp
options.AddAspNetIdentityMigration(migrationOptions =>{    migrationOptions.ConnectionString = "existing-aspnet-identity-db";});

Key points:

  • Imports users, roles, and claims from existing ASP.NET Identity tables
  • Password hashes are preserved (users can still log in with existing passwords)
  • Migration runs once; subsequent runs skip already-imported users
  • After migration, users can enroll in passwordless methods

Common Anti-Patterns

❌ Configuring storage outside AddUserManagement() — storage config must be inside the options lambda ❌ Using UseAuthentication() instead of UseIdentityServer() — IdentityServer middleware handles auth ❌ Skipping CreateIfNotExistsAsync() — database tables won't exist on first run ❌ Using in-memory storage in production — data is lost on restart

Common Pitfalls

  1. Storage configuration location: AddSqliteStore()/AddPostgreSqlStore() must be called inside the AddUserManagement(options => { }) lambda, not on the top-level builder.
  2. .NET 10 required: User Management requires .NET 10 SDK or later.
  3. OTP dispatcher required: Without an IOtpDispatcher, the default OTP flow cannot send codes. Register ConsoleOtpDispatcher for development.
  4. LoginUrl/LogoutUrl: Must be set in IdentityServer options to point to your account pages.
  5. Schema creation: Call IDatabaseSchema.CreateIfNotExistsAsync() before the app starts handling requests.

Related Skills

  • identityserver-configuration — IdentityServer host configuration and options
  • identityserver-ui-flows — Login/logout UI flows
  • identityserver-upgrade-v7-to-v8 — Migration guide for v8 (includes User Management as new feature)
  • aspnetcore-authentication — ASP.NET Core authentication fundamentals

来源与署名

来源:DuendeSoftware/duende-skills位于skills/identityserver-usermanagement提交fb32edc

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架