You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor .NET 8集成Azure AD B2C登录重定向signin-oidc遇关联错误

Blazor .NET 8 Server + Azure AD B2C 关联错误(correlation_error)问题

问题现象

  • 基于.NET 8的Blazor Server应用,采用Azure AD B2C实现身份验证,部署在应用网关之后
  • 部分用户登录成功后被重定向到https://example.com/signin-oidc,页面卡住并显示correlation_error
  • 用户手动删除URL中的signin-oidc,直接访问https://example.com即可正常进入主页
  • 问题并非所有用户每次登录都会触发,属于偶发现象

当前配置及实现

Azure AD B2C 配置

"AzureAdB2C": {
    "Instance": "https://my-b2c.b2clogin.com",
    "ClientId": "",
    "Domain": "my-b2c.onmicrosoft.com",
    "ObjectId": "",
    "TenantId": "",
    "ClientSecret": "",
    "CallbackPath": "/signin-oidc",
    "SignUpSignInPolicyId": "B2C_1_MyB2C_SignIn",
    "SignedOutCallbackPath": "/signout",
}

已在Azure AD B2C应用注册中,将https://example.com/signin-oidc配置为合法重定向URL

自定义重定向URL代码实现

由于应用使用应用网关配置的自定义域名,通过环境变量/配置文件动态设置重定向URL,启动阶段代码如下:

if (!string.IsNullOrEmpty(builder.Configuration.GetValue<string>($"{authType}:CustomRedirectBaseUrl")))
{
    var redirectUrlBase = builder.Configuration.GetValue<string>($"{authType}:CustomRedirectBaseUrl");
    var redirectUrl = redirectUrlBase + builder.Configuration.GetValue<string>($"{authType}:CallbackPath");

    logger.LogInformation($"Custom redirect url is found: {redirectUrl}");

    builder.Services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, opts =>
    {
        opts.Events = new OpenIdConnectEvents
        {
            OnRedirectToIdentityProvider = async context =>
            {
                logger.LogInformation($"OnRedirectToIdentityProvider: RedirectUri set to '{redirectUrl}'");
                context.ProtocolMessage.RedirectUri = redirectUrl;
                await Task.Yield();
            },
            OnRedirectToIdentityProviderForSignOut = async context =>
            {
                logger.LogInformation($"OnRedirectToIdentityProviderForSignOut: PostLogoutRedirectUri set to '{redirectUrlBase}'");
                context.ProtocolMessage.PostLogoutRedirectUri = redirectUrlBase;
                await Task.Yield();
            }
        };
    });
}

补充验证信息

  • B2C登录请求URL截图确认:请求中包含正确的重定向URI参数
  • B2C应用注册身份验证配置截图确认:已添加https://example.com/signin-oidc作为重定向URL
  • Azure Web应用环境变量截图确认:已配置CustomRedirectBaseUrl为https://example.com
  • 系统日志截图确认:重定向URL已被正确设置为https://example.com/signin-oidc

内容的提问来源于stack exchange,提问作者user29875125

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 02:38:16