You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开发环境中Microsoft身份验证中间件突然异常缓慢问题排查

ASP.NET Core Web API本地开发中Azure Service令牌身份验证导致60秒延迟问题

我正在本地开发一个ASP.NET Core Web API,配置了两种JWT Bearer身份验证方案:一种对接自研身份提供商的「user」令牌,另一种对接Azure租户颁发的「service」令牌,配置代码无特殊之处。

近期本地开发环境里,受保护的端点响应突然异常缓慢,响应时长可达60秒左右。排查后发现仅要求service令牌的端点存在此问题:比如某端点同时支持user或service令牌,移除service令牌要求后,用user令牌调用响应完全正常。

另外,在身份验证前的中间件设断点会快速触发,但控制器内的断点要等很久才会触发。由此推断问题出在JWT Bearer身份验证中间件内部,但暂时没定位到具体原因。

已做的排查步骤

  • 网络流量监控:用Fiddler监控应用内部流量(执行命令netsh winhttp set proxy 127.0.0.1:8888),未发现耗时较长的请求。值得注意的是,日志里没有针对Azure租户well-known发现文档的请求,只有自研user令牌的发现文档请求,其余均为App Insights相关请求:
#   Result  Protocol    Host    URL Body    Caching Content-Type    Process Comments    Custom  
12  200 HTTPS   my.identity.local:44119 /.well-known/openid-configuration   2,104       application/json; charset=UTF-8 identity.app:800            
13  200 HTTPS   my.identity.local:44119 /.well-known/openid-configuration/jwks  463     application/json; charset=UTF-8 identity.app:800            
17  200 HTTP    www.msftconnecttest.com /connecttest.txt    22  max-age=30, must-revalidate text/plain  svchost:3132            
18  502 HTTP    ipv6.msftconnecttest.com    /connecttest.txt    512 no-cache, must-revalidate   text/html; charset=UTF-8    svchost:3132            
24  200 HTTPS   fe2cr.update.microsoft.com  /v6/ClientWebService/client.asmx    2,155   private text/xml; charset=utf-8 svchost:8068            
34  502 HTTP    ipv6.msftconnecttest.com    /connecttest.txt    512 no-cache, must-revalidate   text/html; charset=UTF-8    svchost:3132            
35  200 HTTP    www.msftconnecttest.com /connecttest.txt    22  max-age=30, must-revalidate text/plain  svchost:3132            
47  200 HTTPS   fe2cr.update.microsoft.com  /v6/ClientWebService/client.asmx    2,149   private text/xml; charset=utf-8 svchost:8068                    
  • JWT事件监听:针对Service方案仅触发了MessageReceived(触发极快)和AuthenticationFailed(延迟较长时间后触发,符合预期,因为使用的并非service令牌),未获得有效线索。

目前已排除CPU受限的可能,但没有其他排查思路。该问题仅在近几天出现,且我几乎未修改API代码库。拥有付费Azure账户,会不会是Azure速率限制导致?

求各位提供排查建议,当前的缓慢问题已经严重影响开发效率。

Service令牌身份验证配置代码

private static void AddServiceTokenAuthenticationIfRequired(this AuthenticationBuilder authBuilder, IServiceCollection services, AuthenticationSettings settings)
{
    if (!settings.SupportServiceTokens)
    {
        return;
    }

    services.AddSingleton<CustomServiceAuthenticationEvents>();

    var tenantId = settings.TenantId ?? throw new Exception("Token tenant not configured");
    var authority = $"https://sts.windows.net/{tenantId}";
    var audience = settings.DefaultTokenAudience ?? throw new Exception("Token audience not configured");

    authBuilder.AddJwtBearer(AuthenticationSchemes.Service, options =>
    {
        options.Audience = audience;
        options.Authority = new Uri(authority).AbsoluteUri;
        options.TokenValidationParameters.NameClaimType = JwtClaimTypes.Subject;
        options.TokenValidationParameters.ValidateIssuer = true;
        options.TokenValidationParameters.ValidIssuers = [$"{authority}/"];
        options.TokenValidationParameters.ValidateAudience = true;
        options.TokenValidationParameters.ValidateIssuerSigningKey = true;
        options.TokenValidationParameters.ValidateLifetime = true;
        options.TokenValidationParameters.LogValidationExceptions = true;
        options.EventsType = typeof(CustomServiceAuthenticationEvents);
        options.MapInboundClaims = false;
    });
}

内容的提问来源于stack exchange,提问作者Tom Troughton

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 04:00:57