You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 8 Blazor独立账号下Minimal API授权调用异常排查

解决方案:Blazor独立账号模式下Minimal API认证失败问题

核心错误分析

  1. AuthorizationMessageHandler误用:Microsoft.AspNetCore.Components.WebAssembly.Authentication.IAccessTokenProvider是WebAssembly客户端专属服务,不能在Server端注册CustomAuthorizationMessageHandler——这是导致服务构造失败的直接原因。该Handler的作用是在客户端请求时自动附加认证Token,仅能配置在Client项目中。

  2. Server端配置加载冲突:.NET 8 Blazor Web App的WebApplication.CreateBuilder默认已自动加载appsettings.json、appsettings.{Environment}.json等配置文件,手动重复调用builder.Configuration.AddJsonFile()会干扰默认加载逻辑,可能导致认证相关配置项(如Identity、Cookie规则)未被正确读取,进而引发认证失败。

分步修复方案

1. 移除Server端错误的Handler配置

删除Server端Program.cs中所有与CustomAuthorizationMessageHandler相关的代码,包括服务注册和HttpClient的Handler绑定。若Server端仅作为API提供者,无需向Client发起请求,甚至可以直接移除该命名HttpClient的配置。

2. 正确配置Client端的认证HttpClient

在Client项目的Program.cs中,配置带认证消息Handler的HttpClient,确保请求自动携带Token:

// 注册自定义授权消息Handler(Client项目专属)
builder.Services.AddScoped<CustomAuthorizationMessageHandler>();

// 配置调用Server API的HttpClient,自动附加认证Token
builder.Services.AddHttpClient("ServerAPI", client =>
{
    client.BaseAddress = new Uri(builder.HostEnvironment.BaseAddress);
})
.AddHttpMessageHandler<CustomAuthorizationMessageHandler>();

// 注册ApiService,注入配置好的HttpClient
builder.Services.AddScoped<ApiService>(sp =>
{
    var factory = sp.GetRequiredService<IHttpClientFactory>();
    return new ApiService(builder.HostEnvironment.BaseAddress, factory);
});

对应的CustomAuthorizationMessageHandler实现(放在Client项目中):

using Microsoft.AspNetCore.Components.WebAssembly.Authentication;

public class CustomAuthorizationMessageHandler : AuthorizationMessageHandler
{
    public CustomAuthorizationMessageHandler(IAccessTokenProvider provider, NavigationManager navigationManager)
        : base(provider, navigationManager)
    {
        // 指定需要授权的Server API地址(替换为你的实际地址)
        ConfigureHandler(authorizedUrls: new[] { "https://localhost:7241" });
    }
}

3. 修复Server端配置加载逻辑

删除Server端Program.cs开头手动添加的配置文件读取代码:

// 移除以下重复配置代码
IHostEnvironment env = builder.Environment;

builder.Configuration
    .AddJsonFile("appsettings.json", optional: true, reloadOnChange: true)
    .AddJsonFile($"appsettings.{env.EnvironmentName}.json", true, true);

WebApplication.CreateBuilder会自动处理配置文件加载(含环境变量、用户机密),无需手动重复添加。若需自定义配置源,应在默认逻辑基础上追加,而非重复调用AddJsonFile。

4. 验证Server端认证配置顺序

确保Server端的认证、Identity、中间件配置顺序正确:

// 先注册DbContext
builder.Services.AddDbContext<ApplicationDbContext>(options =>
    options.UseSqlServer(builder.Configuration.GetConnectionString("DefaultConnection")));

// 配置认证与Identity服务
builder.Services.AddAuthentication(options =>
{
    options.DefaultScheme = IdentityConstants.ApplicationScheme;
    options.DefaultSignInScheme = IdentityConstants.ExternalScheme;
})
.AddIdentityCookies();

builder.Services.AddIdentityCore<ApplicationUser>(options => options.SignIn.RequireConfirmedAccount = true)
    .AddRoles<IdentityRole>()
    .AddEntityFrameworkStores<ApplicationDbContext>()
    .AddSignInManager()
    .AddDefaultTokenProviders();

// 添加授权服务
builder.Services.AddAuthorization();

// 启用中间件(顺序不可颠倒)
app.UseAuthentication();
app.UseAuthorization();

// 映射Minimal API端点
app.MapClientEndpoints();

额外验证点

  • 确认Client端ApiService使用的是ServerAPI命名客户端,请求地址正确指向Server端API路由。
  • 登录后通过浏览器开发者工具的Network面板检查请求头,确认是否包含Authorization: Bearer {token}(JWT模式)或正确的认证Cookie。
  • 对比可运行的最小化项目,确保Server端中间件顺序符合规范(UseAuthentication必须在UseAuthorization之前,且在端点映射前)。

内容的提问来源于stack exchange,提问作者Enrico

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 12:40:56