开发环境中Microsoft身份验证中间件突然异常缓慢问题排查
ASP.NET Core Web API本地开发中Azure Service令牌身份验证导致60秒延迟问题
我正在本地开发一个ASP.NET Core Web API,配置了两种JWT Bearer身份验证方案:一种对接自研身份提供商的「user」令牌,另一种对接Azure租户颁发的「service」令牌,配置代码无特殊之处。
近期本地开发环境里,受保护的端点响应突然异常缓慢,响应时长可达60秒左右。排查后发现仅要求service令牌的端点存在此问题:比如某端点同时支持user或service令牌,移除service令牌要求后,用user令牌调用响应完全正常。
另外,在身份验证前的中间件设断点会快速触发,但控制器内的断点要等很久才会触发。由此推断问题出在JWT Bearer身份验证中间件内部,但暂时没定位到具体原因。
已做的排查步骤
- 网络流量监控:用Fiddler监控应用内部流量(执行命令
netsh winhttp set proxy 127.0.0.1:8888),未发现耗时较长的请求。值得注意的是,日志里没有针对Azure租户well-known发现文档的请求,只有自研user令牌的发现文档请求,其余均为App Insights相关请求:
# Result Protocol Host URL Body Caching Content-Type Process Comments Custom 12 200 HTTPS my.identity.local:44119 /.well-known/openid-configuration 2,104 application/json; charset=UTF-8 identity.app:800 13 200 HTTPS my.identity.local:44119 /.well-known/openid-configuration/jwks 463 application/json; charset=UTF-8 identity.app:800 17 200 HTTP www.msftconnecttest.com /connecttest.txt 22 max-age=30, must-revalidate text/plain svchost:3132 18 502 HTTP ipv6.msftconnecttest.com /connecttest.txt 512 no-cache, must-revalidate text/html; charset=UTF-8 svchost:3132 24 200 HTTPS fe2cr.update.microsoft.com /v6/ClientWebService/client.asmx 2,155 private text/xml; charset=utf-8 svchost:8068 34 502 HTTP ipv6.msftconnecttest.com /connecttest.txt 512 no-cache, must-revalidate text/html; charset=UTF-8 svchost:3132 35 200 HTTP www.msftconnecttest.com /connecttest.txt 22 max-age=30, must-revalidate text/plain svchost:3132 47 200 HTTPS fe2cr.update.microsoft.com /v6/ClientWebService/client.asmx 2,149 private text/xml; charset=utf-8 svchost:8068
- JWT事件监听:针对Service方案仅触发了
MessageReceived(触发极快)和AuthenticationFailed(延迟较长时间后触发,符合预期,因为使用的并非service令牌),未获得有效线索。
目前已排除CPU受限的可能,但没有其他排查思路。该问题仅在近几天出现,且我几乎未修改API代码库。拥有付费Azure账户,会不会是Azure速率限制导致?
求各位提供排查建议,当前的缓慢问题已经严重影响开发效率。
Service令牌身份验证配置代码
private static void AddServiceTokenAuthenticationIfRequired(this AuthenticationBuilder authBuilder, IServiceCollection services, AuthenticationSettings settings) { if (!settings.SupportServiceTokens) { return; } services.AddSingleton<CustomServiceAuthenticationEvents>(); var tenantId = settings.TenantId ?? throw new Exception("Token tenant not configured"); var authority = $"https://sts.windows.net/{tenantId}"; var audience = settings.DefaultTokenAudience ?? throw new Exception("Token audience not configured"); authBuilder.AddJwtBearer(AuthenticationSchemes.Service, options => { options.Audience = audience; options.Authority = new Uri(authority).AbsoluteUri; options.TokenValidationParameters.NameClaimType = JwtClaimTypes.Subject; options.TokenValidationParameters.ValidateIssuer = true; options.TokenValidationParameters.ValidIssuers = [$"{authority}/"]; options.TokenValidationParameters.ValidateAudience = true; options.TokenValidationParameters.ValidateIssuerSigningKey = true; options.TokenValidationParameters.ValidateLifetime = true; options.TokenValidationParameters.LogValidationExceptions = true; options.EventsType = typeof(CustomServiceAuthenticationEvents); options.MapInboundClaims = false; }); }
内容的提问来源于stack exchange,提问作者Tom Troughton
相关产品推荐
相关产品推荐

