.NET Core 8部署IIS 10后PATCH/PUT/DELETE请求遭404.6拒绝求助
我正在为一个.NET Core 8网站添加API,在Visual Studio的IIS Express本地运行时,PATCH、PUT、DELETE请求均可正常工作,但部署到服务器的IIS 10后,这些请求被拒绝并返回404错误,IIS日志显示具体错误为404.6(未找到 - 请求过滤模块配置为拒绝该HTTP动词)。GET和POST请求始终可以正常执行。
我已通过网络研究对web.config进行了所有能找到的调整,但均无效果——包括移除WebDAV、删除并重新添加指定完整动词列表的aspNetCore和ExtensionlessUrlHandler-Integrated-4.0处理器。
我曾尝试在<security>节中添加以下配置,但由于只要包含任何<add>标签站点就无法重启,因此已将其移除:
<requestFiltering> <verbs> <add verb="GET" allowed="true" /> <add verb="HEAD" allowed="true" /> <add verb="POST" allowed="true" /> <add verb="PUT" allowed="true" /> <add verb="PATCH" allowed="true" /> <add verb="DELETE" allowed="true" /> <add verb="OPTIONS" allowed="true" /> </verbs> </requestFiltering>
我曾尝试在<add>标签前添加对应的<remove>标签,假设是重复添加导致问题,但并无帮助。只要<verbs>节为空,<requestFiltering>和<verbs>标签不会造成问题。
当前web.config配置如下:
<?xml version="1.0" encoding="utf-8"?> <configuration> <location path="." inheritInChildApplications="false"> <system.web> <httpCookies httpOnlyCookies="true" /> </system.web> <system.webServer> <modules runAllManagedModulesForAllRequests="true"> <remove name="WebDAVModule" /> </modules> <httpProtocol> <customHeaders> <add name="X-Content-Type-Options" value="nosniff" /> <add name="Content-Security-Policy" value="script-src 'self' 'unsafe-hashes' 'sha256-[...]/[...]';" /> <add name="Referrer-Policy" value="same-origin" /> </customHeaders> </httpProtocol> <rewrite> <outboundRules> <rule name="Use only secure cookies" preCondition="Unsecured cookie"> <match serverVariable="RESPONSE_SET_COOKIE" pattern=".*" negate="false" /> <action type="Rewrite" value="{R:0}; secure" /> </rule> <preConditions> <preCondition name="Unsecured cookie"> <add input="{RESPONSE_SET_COOKIE}" pattern="." /> <add input="{RESPONSE_SET_COOKIE}" pattern=";; secure" negate="true" /> </preCondition> </preConditions> </outboundRules> </rewrite> <handlers> <remove name="WebDAV" /> <remove name="WebAdminHandler-Integrated" /> <remove name="aspNetCore" /> <add name="aspNetCore" path="*" verb="GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS" modules="AspNetCoreModuleV2" resourceType="Unspecified" requireAccess="Script" /> <remove name="ExtensionlessUrlHandler-Integrated-4.0" /> <add name="ExtensionlessUrlHandler-Integrated-4.0" path="*." verb="GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS" type="System.Web.Handlers.TransferRequestHandler" preCondition="integratedMode,runtimeVersionv4.0" /> </handlers> <aspNetCore processPath="dotnet" arguments=".\Frb.Mispl.dll" stdoutLogEnabled="false" stdoutLogFile=".\logs\stdout" hostingModel="inprocess"> <environmentVariables> <environmentVariable name="ASPNETCORE_ENVIRONMENT" value="Development" /> </environmentVariables> </aspNetCore> <security> <authentication> <anonymousAuthentication enabled="true" /> <windowsAuthentication enabled="false" /> </authentication> </security> </system.webServer> </location> </configuration>
修正requestFiltering的动词配置:之前添加
<add>标签导致站点无法重启,是因为没有清除继承的全局规则。改用以下配置,先清空现有规则再添加允许的动词:<security> <requestFiltering> <verbs clear="true"> <add verb="GET" allowed="true"/> <add verb="HEAD" allowed="true"/> <add verb="POST" allowed="true"/> <add verb="PUT" allowed="true"/> <add verb="PATCH" allowed="true"/> <add verb="DELETE" allowed="true"/> <add verb="OPTIONS" allowed="true"/> </verbs> </requestFiltering> </security>检查IIS服务器级别的请求过滤规则:打开IIS管理器,选中服务器节点→「请求过滤」→「HTTP动词」标签,查看全局是否拒绝了PUT/PATCH/DELETE这类动词。如果全局规则有限制,需修改全局允许列表,或用上述站点级配置覆盖。
确认.NET Core托管捆绑包已安装:服务器必须安装对应.NET Core 8版本的托管捆绑包,否则AspNetCoreModuleV2无法正确转发请求,导致动词被IIS拦截。
切换托管模式为OutOfProcess:将web.config中
<aspNetCore>节点的hostingModel从inprocess改为outofprocess,进程内托管可能与IIS请求过滤模块产生冲突。检查应用程序池配置:确保站点对应的应用程序池,「.NET CLR版本」设置为「无托管代码」,错误的.NET Framework版本设置会干扰.NET Core应用的请求处理。
彻底移除WebDAV模块:除了web.config中的移除配置,还需在IIS管理器的站点「模块」列表中确认WebDAV已被移除;若服务器不需要WebDAV功能,直接在「服务器管理器」中卸载WebDAV角色服务。
排查URL重写规则影响:暂时注释掉web.config中的
<rewrite>节点,测试PUT/PATCH/DELETE请求是否正常,排除规则逻辑间接干扰请求动词传递的可能。
内容的提问来源于stack exchange,提问作者Green Grasso Holm

