You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

发布ASP.NET WebForms至IIS后OnRedirectToIdentityProvider未触发

IIS部署后OpenIdConnect重定向事件未触发的排查与解决

问题描述

我有一个ASP.NET WebForms应用及Web API,本地IIS Express环境下,用户访问特定页面时会自动调用自定义Identity Server,触发OnRedirectToIdentityProvider事件。但发布到IIS后,点击登录链接页面仅返回HTTP 200,该事件未触发。

配置代码

app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

app.UseCookieAuthentication(new CookieAuthenticationOptions
{
    AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie,
    AuthenticationMode =  Microsoft.Owin.Security.AuthenticationMode.Passive
});

app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
{
    AuthenticationType = OpenIdConnectAuthenticationDefaults.AuthenticationType, //"oidc";
    ClientId = WebConfigurationManager.AppSettings["ClientId"],
    BackchannelTimeout = System.TimeSpan.FromMinutes(30),
    CallbackPath = new PathString("/Account/Login"),        
    Authority = WebConfigurationManager.AppSettings["Authority"],
    PostLogoutRedirectUri = WebConfigurationManager.AppSettings["PostLogoutRedirectUri"],
    RedirectUri = WebConfigurationManager.AppSettings["RedirectUri"],
    Scope = "openid profile",
    ResponseType = "id_token",
    SaveTokens = true,
    Notifications = new OpenIdConnectAuthenticationNotifications
    {
        AuthenticationFailed = OnAuthenticationFailed,
        SecurityTokenValidated = OnSecurityTokenValidated,
        RedirectToIdentityProvider = OnRedirectToIdentityProvider,
        MessageReceived = OnMessageReceived,
        AuthorizationCodeReceived = OnAuthorizationCodeReceived,
        TokenResponseReceived = OnTokenResponseReceived,
        SecurityTokenReceived = OnSecurityTokenReceived,
    }
});

app.UseStageMarker(PipelineStage.Authenticate);

可能的原因及解决方法

1. Cookie认证模式配置问题

当前CookieAuthentication设置为AuthenticationMode.Passive,被动模式下中间件不会主动触发认证流程,IIS环境的请求管道差异会导致跳转逻辑无法触发。

修改为主动模式,让Cookie中间件参与认证流程:

app.UseCookieAuthentication(new CookieAuthenticationOptions
{
    AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie,
    AuthenticationMode = Microsoft.Owin.Security.AuthenticationMode.Active
});

2. IIS请求管道阶段标记位置错误

UseStageMarker需紧跟在所有认证中间件配置之后,确保认证逻辑在正确的管道阶段执行。调整顺序:

app.UseOpenIdConnectAuthentication(...);
app.UseStageMarker(PipelineStage.Authenticate);

3. IIS模块拦截干扰

IIS默认的Forms Authentication模块会与Owin认证流程冲突,需在Web.config中禁用:

<system.webServer>
  <modules>
    <remove name="FormsAuthentication" />
  </modules>
</system.webServer>

同时设置系统身份验证模式为None:

<system.web>
  <authentication mode="None" />
</system.web>

4. 回调路径与站点配置不匹配

若站点部署在虚拟目录下,CallbackPath和RedirectUri需包含虚拟目录前缀。比如虚拟目录为/MyApp,则CallbackPath应设为/MyApp/Account/Login,确保与IIS站点的绑定地址完全一致。

5. 应用池权限与版本问题

  • 确保应用池身份拥有访问Identity Server的权限;
  • 检查应用池的.NET CLR版本与项目目标框架版本匹配(如项目用.NET Framework 4.8,应用池需对应设置)。

6. 日志排查隐藏错误

在认证事件中添加日志输出,捕获隐藏异常。例如在OnAuthenticationFailed中记录错误:

private Task OnAuthenticationFailed(AuthenticationFailedNotification<OpenIdConnectMessage, OpenIdConnectAuthenticationOptions> notification)
{
    System.IO.File.AppendAllText(@"C:\Logs\AuthError.log", $"认证失败: {notification.Exception.Message}\r\n");
    notification.HandleResponse();
    notification.Response.Redirect("/Error?message=" + notification.Exception.Message);
    return Task.FromResult(0);
}

内容的提问来源于stack exchange,提问作者Daniele Frisenna

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 04:50:08