You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

将ADFS集成到IdentityServer后出现重定向循环及MSIS7042错误求助

ADFS集成IdentityServer时的重定向循环与MSIS7042错误排查解决

问题场景

将ADFS集成到IdentityServer时,使用以下配置代码:

services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
})
.AddCookie()
.AddOpenIdConnect(options =>
{
    options.SignInScheme = "Cookies";
    options.Authority = "https://localhost:5000";
    options.RequireHttpsMetadata = false;
    options.ResponseType = OpenIdConnectResponseType.Code;
    options.UsePkce = false;
    options.Scope.Clear();
    options.Scope.Add("openid");
    options.Scope.Add("profile");
    options.Scope.Add("email");
    options.SaveTokens = true;
    options.MetadataAddress = "https://XXX/adfs/.well-known/openid-configuration";
    options.ClientId = "MY Client ID";
    options.CallbackPath = new PathString("/signin-oidc");
    options.TokenValidationParameters.SaveSigninToken = true;
    options.GetClaimsFromUserInfoEndpoint = true;

    options.Events = new OpenIdConnectEvents
    {
        OnRedirectToIdentityProvider = context =>
        {
            context.HttpContext.Response.Headers.Add("X-Redirect", "Redirecting to ADFS");
            return Task.CompletedTask;
        },
        OnTokenValidated = context =>
        {
            context.HttpContext.Response.Headers.Add("X-TokenValidated", "Token validated successfully");
            return Task.CompletedTask;
        },
        OnAuthenticationFailed = context =>
        {
            context.HttpContext.Response.Headers.Add("X-AuthenticationFailed", "Authentication failed");
            context.Response.Redirect("/Home/Error?message=" + context.Exception.Message);
            context.HandleResponse();
            return Task.CompletedTask;
        }
    };
});

ADFS登录页面可正常登录,但登录后出现多次自动重定向,抛出错误:

OpenIdConnectProtocolException: Message contains error: 'server_error', error_description: 'MSIS9604%3a+An+error+occurred.+The+authorization+server+was+not+able+to+fulfill+the+request.', error_uri: 'error_uri is null'.

服务器事件查看器记录错误:

Encountered error during OAuth authorization request.

Additional Data

Exception details:
Microsoft.IdentityServer.Web.InvalidRequestException: MSIS7042: The same client browser session has made '6' requests in the last '7' seconds. Contact your administrator for details.
at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.UpdateLoopDetectionCookie(WrappedHttpListenerContext context)
at Microsoft.IdentityServer.Web.Protocols.PassiveProtocolHandler.ProcessCommonCookiesInLastAuthenticationStage(ProtocolContext context)
at Microsoft.IdentityServer.Web.Protocols.OAuth.OAuthAuthorization.OAuthAuthorizationProtocolHandler.SendAuthorizationResponse(OAuthAuthorizationRequestContext authContext, OAuthAuthorizationResponseMessage authResponse)

排查与解决方法

1. 修正Authority配置冲突

配置中同时指定了Authority和MetadataAddress,二者存在冲突。由于已经通过MetadataAddress指定了ADFS的OpenID Connect元数据地址,无需再将Authority设为IdentityServer的地址:

  • 移除options.Authority = "https://localhost:5000";,或将其替换为ADFS的根地址(如https://XXX/adfs)。

2. 确保SignInScheme一致性

配置中AddCookie()未显式指定方案名称,但options.SignInScheme = "Cookies";,可能导致认证状态无法正常持久化,引发重复挑战:

  • 将AddCookie()改为AddCookie("Cookies");,显式指定Cookie认证方案名称,保证与SignInScheme配置一致。

3. 临时关闭UserInfo端点获取(排查用)

GetClaimsFromUserInfoEndpoint = true可能在ADFS环境中触发额外请求,导致循环。可以先关闭该选项验证问题是否解决:

  • 设置options.GetClaimsFromUserInfoEndpoint = false;,若问题消失,再排查ADFS的UserInfo端点配置或权限。

4. 检查ADFS客户端回调URI匹配

ADFS客户端配置中的重定向URI必须与代码中的CallbackPath完全一致,包括域名、路径、大小写:

  • 登录ADFS管理控制台,确认注册客户端的重定向URI为https://<你的应用域名>/signin-oidc,避免因URI不匹配导致ADFS拒绝回调,引发重定向循环。

5. 调整ADFS循环检测阈值(临时缓解)

MSIS7042错误是ADFS的防循环检测机制触发的,若上述配置修正后仍有问题,可临时调整阈值:

  • 在ADFS管理控制台中,进入ADFS > 服务 > 认证策略 > 编辑全局认证策略 > 高级,调整循环检测Cookie的超时时间或请求次数阈值。注意:这只是临时缓解手段,核心需解决代码中的重定向根源。

6. 验证HTTPS配置

即使本地测试设置了RequireHttpsMetadata = false,也要确保应用和ADFS的HTTPS配置正常,避免因协议问题导致请求失败,引发重复挑战。

内容的提问来源于stack exchange,提问作者Hossam Attia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 21:13:24