You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 8部署IIS 10后PATCH/PUT/DELETE请求遭404.6拒绝求助

问题描述

我正在为一个.NET Core 8网站添加API,在Visual Studio的IIS Express本地运行时,PATCH、PUT、DELETE请求均可正常工作,但部署到服务器的IIS 10后,这些请求被拒绝并返回404错误,IIS日志显示具体错误为404.6(未找到 - 请求过滤模块配置为拒绝该HTTP动词)。GET和POST请求始终可以正常执行。

我已通过网络研究对web.config进行了所有能找到的调整,但均无效果——包括移除WebDAV、删除并重新添加指定完整动词列表的aspNetCore和ExtensionlessUrlHandler-Integrated-4.0处理器。

我曾尝试在<security>节中添加以下配置,但由于只要包含任何<add>标签站点就无法重启,因此已将其移除:

<requestFiltering>
  <verbs>
    <add verb="GET" allowed="true" />
    <add verb="HEAD" allowed="true" />
    <add verb="POST" allowed="true" />
    <add verb="PUT" allowed="true" />
    <add verb="PATCH" allowed="true" />
    <add verb="DELETE" allowed="true" />
    <add verb="OPTIONS" allowed="true" />
  </verbs>
</requestFiltering>

我曾尝试在<add>标签前添加对应的<remove>标签,假设是重复添加导致问题,但并无帮助。只要<verbs>节为空,<requestFiltering>和<verbs>标签不会造成问题。

当前web.config配置如下:

<?xml version="1.0" encoding="utf-8"?>
<configuration>
    <location path="." inheritInChildApplications="false">
        <system.web>
            <httpCookies httpOnlyCookies="true" />  
        </system.web>
        <system.webServer>
            <modules runAllManagedModulesForAllRequests="true">
                <remove name="WebDAVModule" />
            </modules>
            <httpProtocol>
                <customHeaders>
                    <add name="X-Content-Type-Options" value="nosniff" />
                    <add name="Content-Security-Policy" value="script-src 'self' 'unsafe-hashes' 'sha256-[...]/[...]';" />
                    <add name="Referrer-Policy" value="same-origin" />
                </customHeaders>
            </httpProtocol>
            <rewrite>
                <outboundRules>
                    <rule name="Use only secure cookies" preCondition="Unsecured cookie">
                        <match serverVariable="RESPONSE_SET_COOKIE" pattern=".*" negate="false" />
                        <action type="Rewrite" value="{R:0}; secure" />
                    </rule>
                    <preConditions>
                        <preCondition name="Unsecured cookie">
                            <add input="{RESPONSE_SET_COOKIE}" pattern="." />
                            <add input="{RESPONSE_SET_COOKIE}" pattern=";; secure" negate="true" />
                        </preCondition>
                    </preConditions>
                </outboundRules>
            </rewrite>
            <handlers>
                <remove name="WebDAV" />
                <remove name="WebAdminHandler-Integrated" />
                <remove name="aspNetCore" />
                <add name="aspNetCore" path="*" verb="GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS" modules="AspNetCoreModuleV2" resourceType="Unspecified" requireAccess="Script" />
                <remove name="ExtensionlessUrlHandler-Integrated-4.0" />
                <add name="ExtensionlessUrlHandler-Integrated-4.0"
                    path="*."
                    verb="GET,HEAD,POST,PUT,PATCH,DELETE,OPTIONS"
                    type="System.Web.Handlers.TransferRequestHandler"
                    preCondition="integratedMode,runtimeVersionv4.0" />
            </handlers>
            <aspNetCore processPath="dotnet" arguments=".\Frb.Mispl.dll" stdoutLogEnabled="false" stdoutLogFile=".\logs\stdout" hostingModel="inprocess">
                <environmentVariables>
                    <environmentVariable name="ASPNETCORE_ENVIRONMENT" value="Development" />
                </environmentVariables>
            </aspNetCore>
            <security>
                <authentication>
                    <anonymousAuthentication enabled="true" />
                    <windowsAuthentication enabled="false" />
                </authentication>
            </security>
        </system.webServer>
    </location>
</configuration>
可行的解决思路
  • 修正requestFiltering的动词配置:之前添加<add>标签导致站点无法重启,是因为没有清除继承的全局规则。改用以下配置,先清空现有规则再添加允许的动词:

    <security>
      <requestFiltering>
        <verbs clear="true">
          <add verb="GET" allowed="true"/>
          <add verb="HEAD" allowed="true"/>
          <add verb="POST" allowed="true"/>
          <add verb="PUT" allowed="true"/>
          <add verb="PATCH" allowed="true"/>
          <add verb="DELETE" allowed="true"/>
          <add verb="OPTIONS" allowed="true"/>
        </verbs>
      </requestFiltering>
    </security>
    
  • 检查IIS服务器级别的请求过滤规则:打开IIS管理器,选中服务器节点→「请求过滤」→「HTTP动词」标签,查看全局是否拒绝了PUT/PATCH/DELETE这类动词。如果全局规则有限制,需修改全局允许列表,或用上述站点级配置覆盖。

  • 确认.NET Core托管捆绑包已安装:服务器必须安装对应.NET Core 8版本的托管捆绑包,否则AspNetCoreModuleV2无法正确转发请求,导致动词被IIS拦截。

  • 切换托管模式为OutOfProcess:将web.config中<aspNetCore>节点的hostingModel从inprocess改为outofprocess,进程内托管可能与IIS请求过滤模块产生冲突。

  • 检查应用程序池配置:确保站点对应的应用程序池,「.NET CLR版本」设置为「无托管代码」,错误的.NET Framework版本设置会干扰.NET Core应用的请求处理。

  • 彻底移除WebDAV模块:除了web.config中的移除配置,还需在IIS管理器的站点「模块」列表中确认WebDAV已被移除;若服务器不需要WebDAV功能,直接在「服务器管理器」中卸载WebDAV角色服务。

  • 排查URL重写规则影响:暂时注释掉web.config中的<rewrite>节点,测试PUT/PATCH/DELETE请求是否正常,排除规则逻辑间接干扰请求动词传递的可能。

内容的提问来源于stack exchange,提问作者Green Grasso Holm

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.16 05:59:51