You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在ASP.NET Core中集成Google登录与JWT认证?遇重定向问题求助

问题分析

你的核心问题是Google认证中间件默认使用/signin-google作为回调路径,但你没有将该路径映射到自定义的GoogleCallback接口,同时RedirectUri配置存在路径解析问题,导致认证成功后重定向异常。


修复步骤

1. 显式配置Google认证的回调路径

修改AddGoogle配置,指定与你的GoogleCallback接口匹配的CallbackPath,避免使用默认路径:

builder.Services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme;
})
.AddGoogle(googleOptions =>
{
    googleOptions.ClientId = builder.Configuration["Google:ClientID"];
    googleOptions.ClientSecret = builder.Configuration["Google:ClientSecret"];
    // 绑定到你的回调接口路由(需与控制器路由前缀匹配)
    googleOptions.CallbackPath = "/api/auth/google-callback";
})
.AddJwtBearer(options =>
{
    // 原JWT配置保留
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuerSigningKey = true,
        IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(builder.Configuration["JWT:Key"])),
        ValidateIssuer = true,
        ValidIssuer = builder.Configuration["JWT:Issuer"],
        ValidateAudience = true,
        ValidAudience = builder.Configuration["JWT:Audience"],
        ValidateLifetime = true,
        ClockSkew = TimeSpan.Zero
    };
});

2. 修正登录接口的重定向URI

使用绝对URL生成RedirectUri,避免相对路径解析错误:

[HttpGet("google-login")]
public IActionResult GoogleLogin()
{
    var properties = new AuthenticationProperties
    {
        // 生成完整绝对路径,适配HTTPS/端口等环境
        RedirectUri = Url.Action("GoogleCallback", "Auth", null, Request.Scheme)
    };
    return Challenge(properties, GoogleDefaults.AuthenticationScheme);
}

3. 完善回调接口的认证逻辑

明确指定Google认证方案获取登录结果,同时补充用户信息处理与JWT生成逻辑:

[HttpGet("google-callback")]
public async Task<IActionResult> GoogleCallback()
{
    // 明确使用Google认证方案获取登录凭证
    var result = await HttpContext.AuthenticateAsync(GoogleDefaults.AuthenticationScheme);
    if (!result.Succeeded)
        return Unauthorized();

    // 从Claims中提取Google返回的用户信息
    var email = result.Principal.FindFirstValue(ClaimTypes.Email);
    var fullName = result.Principal.FindFirstValue(ClaimTypes.Name);
    var givenName = result.Principal.FindFirstValue(ClaimTypes.GivenName);

    // 数据库操作:查找/创建用户,更新邮箱、姓名等信息
    // var user = await _userRepository.GetByEmailAsync(email);
    // if (user == null) { /* 创建新用户逻辑 */ }
    // else { user.FullName = fullName; await _userRepository.UpdateAsync(user); }

    // 生成JWT令牌(复用原有JWT生成逻辑)
    var token = GenerateJwtToken(result.Principal);

    // 前后端分离场景返回Token,或重定向到前端页面并携带Token
    return Ok(new { AccessToken = token });
}

4. 校验Google开发者控制台配置

确保Google Cloud Console的OAuth2客户端设置中,已添加匹配的回调URL,格式示例:

https://localhost:5001/api/auth/google-callback

注意端口号、HTTP/HTTPS协议需与本地运行环境完全一致。

5. 确认中间件顺序

确保认证、授权中间件在路由中间件之前启用:

app.UseHttpsRedirection();

// 先启用认证,再启用授权
app.UseAuthentication();
app.UseAuthorization();

app.MapControllers();

内容的提问来源于stack exchange,提问作者Anuj Karki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 19:27:39