You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Blazor集成Azure B2C认证后/signin-oidc连接失败排查求助

问题:Azure B2C认证后跳转/signin-oidc失败,无关键事件日志

在.NET Blazor应用中使用Azure B2C完成认证(Azure登录日志显示“Success”)后,页面跳转至https://localhost: /signin-oidc,返回“Refused to connect. /sign-oidc”错误。目前仅能记录OnRedirectToIdentityProvider事件,OnRemoteFailure、OnTokenResponseReceived等关键认证事件无日志输出,缺少有效错误日志用于排查问题。

认证配置代码

services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
.AddMicrosoftIdentityWebApp(options =>
{
    options.RemoteAuthenticationTimeout = TimeSpan.FromSeconds(10);
    builder.Configuration.Bind("OpenIDConnect", options);

    options.Events = new OpenIdConnectEvents
    {
        OnRedirectToIdentityProvider = async ctxt =>
        {
            logger.Info($"On Redirect To Identity Provider : {ctxt.Request.Host.Value}");
            await Task.Yield();
        },
        OnAuthenticationFailed = async ctxt =>
        {
            logger.Info($"On Authentication Failed");
            Console.WriteLine("On Authentication Failed");
            await Task.Yield();
        },
        OnSignedOutCallbackRedirect = async ctxt =>
        {
            logger.Info($"On Signed Out Callback Redirect");

            ctxt.HttpContext.Response.Redirect(ctxt.Options.SignedOutRedirectUri);
            ctxt.HandleResponse();
            await Task.Yield();
        },
        OnMessageReceived = async ctxt =>
        {
            logger.Info($"On Message Received : {ctxt.Request.Path.Value}");
        },
        OnAuthorizationCodeReceived = async context =>
        {
            logger.Info("Authorization Code Received");

            Console.WriteLine("Authorization Code Received");
        },
        OnTokenValidated = async context =>
        {
            logger.Info("Token Validated");

            Console.WriteLine("Token Validated");
        },
        OnRemoteFailure = async ctxt =>
        {
            logger.Info($"On Remote Failure : {ctxt.Failure?.Message}");
            ctxt.Response.Redirect("/");
            ctxt.HandleResponse();

            Console.WriteLine("On Remote Failure");

        },
        OnTokenResponseReceived = async ctxt =>
        {
            logger.Info($"On Access Denied");

            Console.WriteLine("OnTokenResponseReceived");
        },
        OnTicketReceived = async ctxt =>
        {
            logger.Info($"On Ticket Received : {ctxt.Request.Path.Value}");
         }
    };
});

错误排查与解决建议

一、解决跳转失败问题

  • 修正回调地址配置:Azure B2C应用注册中的重定向URI必须与应用内配置的signin-oidc地址完全匹配,注意端口号不能缺失(当前跳转地址localhost:后为空,大概率是配置里的回调地址端口未正确设置)。
  • 调整认证超时时间:当前RemoteAuthenticationTimeout设置为10秒过短,建议调整为30秒以上,避免认证流程因超时中断。
  • 验证HTTPS有效性:确保Blazor应用启用HTTPS,且localhost的HTTPS证书有效,浏览器会拒绝连接未信任的HTTPS地址。
  • 排查路由冲突:确认应用中未自定义/signin-oidc路由,该地址是OpenID Connect中间件的默认回调路由,不能被自定义路由覆盖。

二、完善日志记录

  • 补全事件异步处理:部分事件(如OnMessageReceived)未添加await Task.Yield();,可能导致日志未被正确执行,所有事件方法末尾都需补充该语句。
  • 增加上下文细节日志:在事件中记录更详细的上下文信息,例如:
    • 在OnRemoteFailure中添加logger.Info($"On Remote Failure StackTrace: {ctxt.Failure?.StackTrace}");
    • 在OnMessageReceived中添加logger.Info($"On Message Received Query: {ctxt.Request.QueryString}");
  • 启用Identity组件详细日志:在appsettings.json中添加日志配置,开启Microsoft Identity相关组件的Debug级别日志:
    "Logging": {
      "LogLevel": {
        "Microsoft.Identity.Web": "Debug",
        "Microsoft.AspNetCore.Authentication": "Debug"
      }
    }
    
  • 添加全局异常捕获:在Program.cs中配置全局异常处理,捕获认证流程中的未处理异常:
    app.UseExceptionHandler(errorApp =>
    {
        errorApp.Run(async context =>
        {
            var exceptionFeature = context.Features.Get<IExceptionHandlerPathFeature>();
            logger.LogError(exceptionFeature.Error, "Unhandled exception at path: {Path}", exceptionFeature.Path);
            await context.Response.WriteAsync("An unexpected error occurred during authentication.");
        });
    });
    

内容的提问来源于stack exchange,提问作者Aishwarya Balaji

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 14:22:11