Identityserver Usermanagement

作者 DuendeSoftwarefb32edc51982無授權條款9 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫4 週前更新

Setting up Duende User Management with IdentityServer: passwordless authentication (OTP, TOTP, passkeys), storage configuration, user lifecycle, and migration from ASP.NET Identity.

AI 產生的概覽

指導在 IdentityServer 中設定 Duende 使用者管理,涵蓋無密碼驗證、儲存、使用者生命週期與移轉。

功能
此技能提供將 Duende 使用者管理加入 Duende IdentityServer 專案的指示。內容涵蓋套件安裝、Program.cs 設定、OTP 派送器、驗證方式、儲存提供者、宣告對應、使用者生命週期,以及從 ASP.NET Identity 移轉。它也列出反模式與常見陷阱。
適用情境
適用於將使用者管理加入 Duende IdentityServer 專案、設定無密碼驗證、設定儲存提供者,或從 ASP.NET Identity 移轉使用者時。
執行需求
需要 .NET 10 SDK 或更新版本,以及 Duende.IdentityServer、Duende.UserManagement.IdentityServer8 和某個 Duende.Storage 套件(SQLite、PostgreSQL 或 SQL Server)。正式環境 OTP 傳送需要 SMTP 認證資訊。不包含指令碼,僅為指示文件。

User Management

When to Use This Skill

  • Adding user management to a Duende IdentityServer project
  • Setting up passwordless authentication (OTP, TOTP, passkeys)
  • Configuring storage providers (PostgreSQL, SQL Server, SQLite)
  • Integrating User Management with IdentityServer for claims and login/logout
  • Managing user profiles, roles, and groups
  • Migrating users from ASP.NET Identity

Core Principles

  • Duende User Management is passwordless-first — OTP email/SMS is the default flow
  • Requires Duende.UserManagement.IdentityServer8 NuGet package + .NET 10
  • Storage is document-based (no EF migrations needed) — schema auto-creates at startup
  • Configuration goes inside AddUserManagement(), not at top level
  • Use app.UseIdentityServer() (not UseAuthentication() separately)

Docs: https://docs.duendesoftware.com/identityserver/usermanagement

Setup

1. Add Packages

bash
dotnet add package Duende.IdentityServerdotnet add package Duende.UserManagement.IdentityServer8dotnet add package Duende.Storage.Sqlite  # or .PostgreSQL, .Mssql

2. Configure Program.cs

csharp
var builder = WebApplication.CreateBuilder(args);
builder.Services.AddIdentityServer(options =>{    options.UserInteraction.LoginUrl = "/Account/Login";    options.UserInteraction.LogoutUrl = "/Account/Logout";})    .AddInMemoryClients(Config.Clients)    .AddInMemoryIdentityResources(Config.IdentityResources)    .AddUserManagement(options =>    {        // Storage (pick one)        options.AddSqliteStore("Data Source=users.db");        // options.AddPostgreSqlStore(connectionString);        // options.AddSqlServerStore(connectionString);
        // OTP delivery        options.UseSmtpOtpDispatcher(smtp =>            builder.Configuration.GetSection("Smtp").Bind(smtp));    });
var app = builder.Build();
// Auto-create database schemavar schema = app.Services.GetRequiredService<IDatabaseSchema>();await schema.CreateIfNotExistsAsync();
app.UseIdentityServer();app.MapRazorPages();app.Run();

3. OTP Dispatcher

Console (development):

csharp
builder.Services.AddSingleton<IOtpDispatcher, ConsoleOtpDispatcher>();

SMTP (production):

csharp
options.UseSmtpOtpDispatcher(x =>{    x.Host = "smtp.example.com";    x.Port = 587;    x.Username = "[email protected]";    x.Password = "secret";    x.FromAddress = "[email protected]";});

Authentication Methods

MethodDescriptionSetup
OTP (default)One-time codes via email/SMSIOtpDispatcher implementation
TOTPAuthenticator apps (RFC 6238)Built-in, user enrollment required
PasskeysWebAuthn/FIDO2 phishing-resistantBuilt-in, browser support required
PasswordsTraditional username/password (PBKDF2)Opt-in, not recommended as primary
ExternalOAuth 2.0 / OIDC federated loginStandard ASP.NET Core auth handlers
Recovery codesSingle-use backup codesAuto-generated during 2FA setup

IdentityServer Integration

AddUserManagement() is called on the IdentityServer builder — it automatically:

  • Registers IProfileService for claims delivery
  • Handles login/logout flows
  • Maps user attributes to identity token claims

Claims Mapping

User profile attributes are mapped to claims based on requested scopes:

  • openid → sub
  • profile → name, given_name, family_name, etc.
  • email → email, email_verified

Custom attributes are available through custom identity resources.

Storage

ProviderPackageConnection
SQLiteDuende.Storage.SqliteData Source=users.db
PostgreSQLDuende.Storage.PostgreSQLStandard connection string
SQL ServerDuende.Storage.MssqlStandard connection string
In-Memory(built-in)Data Source=:memory: (testing only)

Storage is document-based — no EF Core migrations needed. Call IDatabaseSchema.CreateIfNotExistsAsync() at startup to ensure schema exists.

User Lifecycle

  • Creation: Users are created on first authentication (passwordless) or via admin APIs
  • Profiles: Custom attributes stored as key-value pairs, organized in attribute groups
  • Roles & Groups: RBAC support with group membership and role inheritance
  • Deletion: Full user deletion with cascade

Migration from ASP.NET Identity

csharp
options.AddAspNetIdentityMigration(migrationOptions =>{    migrationOptions.ConnectionString = "existing-aspnet-identity-db";});

Key points:

  • Imports users, roles, and claims from existing ASP.NET Identity tables
  • Password hashes are preserved (users can still log in with existing passwords)
  • Migration runs once; subsequent runs skip already-imported users
  • After migration, users can enroll in passwordless methods

Common Anti-Patterns

❌ Configuring storage outside AddUserManagement() — storage config must be inside the options lambda ❌ Using UseAuthentication() instead of UseIdentityServer() — IdentityServer middleware handles auth ❌ Skipping CreateIfNotExistsAsync() — database tables won't exist on first run ❌ Using in-memory storage in production — data is lost on restart

Common Pitfalls

  1. Storage configuration location: AddSqliteStore()/AddPostgreSqlStore() must be called inside the AddUserManagement(options => { }) lambda, not on the top-level builder.
  2. .NET 10 required: User Management requires .NET 10 SDK or later.
  3. OTP dispatcher required: Without an IOtpDispatcher, the default OTP flow cannot send codes. Register ConsoleOtpDispatcher for development.
  4. LoginUrl/LogoutUrl: Must be set in IdentityServer options to point to your account pages.
  5. Schema creation: Call IDatabaseSchema.CreateIfNotExistsAsync() before the app starts handling requests.

Related Skills

  • identityserver-configuration — IdentityServer host configuration and options
  • identityserver-ui-flows — Login/logout UI flows
  • identityserver-upgrade-v7-to-v8 — Migration guide for v8 (includes User Management as new feature)
  • aspnetcore-authentication — ASP.NET Core authentication fundamentals

來源與署名

來源:DuendeSoftware/duende-skills位於skills/identityserver-usermanagement提交fb32edc

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架