You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

登录成功后Web_App_B中User.Identity.IsAuthenticated仍为false的问题

问题:JWT可读取Claim但认证状态未标记为已认证

我有两个Web应用:

  • Web_App_A:处理认证逻辑
  • Web_App_B:实际业务应用

用户在Web_App_A中成功登录后(User.Identity.IsAuthenticated == true),我生成JWT访问令牌并传递给Web_App_B。Web_App_B可以读取该JWT,执行如下代码能得到正确结果:

var UserFullName = claimsPrincipal.FindFirst("UserFullName")?.Value;

但问题是,在Web_App_B中检查认证状态时,User.Identity.IsAuthenticated == false。

两个应用的Program.cs中,以下JWT配置部分完全一致:

// JWT配置
var jwtKey = builder.Configuration["Jwt:Key"]; // 从appsettings读取
var jwtValidIssuer = builder.Configuration["Jwt:ValidIssuer"]; // 从appsettings读取
var jwtValidAudience = builder.Configuration["Jwt:ValidAudience"];  // 从appsettings读取

builder.Services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(options =>
{
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuer = true,
        ValidIssuer = jwtValidIssuer,
        ValidateAudience = true,
        ValidAudience = jwtValidAudience,
        ValidateLifetime = true,
        ValidateIssuerSigningKey = true,
        IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(jwtKey)),
        RoleClaimType = ClaimTypes.Role // 正确解析令牌中的角色
    };
});

内容的提问来源于stack exchange,提问作者Waller

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 12:55:58