.NET 6 Linux应用Azure AD认证redirect_uri异常问题排查
反向代理下.NET 6应用Azure AD认证redirect_uri问题排查与解决
问题背景
部署在httpd反向代理后的.NET 6 Linux应用,重定向到Azure进行认证时触发错误:
AADSTS90102: 'redirect_uri'值必须是有效的绝对URI,请求中的redirect_uri为http%3A%2F%2F%28null%29%2Fsignin-oidc。
相关配置
Program.cs
// Add services to the container. builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme) .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAd")); builder.Services.AddAuthorization(options => { // By default, all incoming requests will be authorized according to the default policy. options.FallbackPolicy = options.DefaultPolicy; }); builder.Services.AddRazorPages() .AddMicrosoftIdentityUI(); var app = builder.Build(); // Configure the HTTP request pipeline. if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Error"); // The default HSTS value is 30 days. You may want to change this for production scenarios. app.UseHsts(); } app.UseForwardedHeaders(); app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseSession(); app.UseAuthentication(); app.UseAuthorization(); app.MapRazorPages(); app.MapControllers(); app.Run();
appsettings.json
"AzureAd": { "Instance": "https://login.microsoftonline.com/", "Domain": "mydomain.com", "TenantId": "xxx", "ClientId": "yyy", "CallbackPath": "/signin-oidc" }
企业应用回调URL
已配置的回调URL为:https://somesite-dev.mydomain.com/signin-oidc
初始httpd配置
ServerName somesite-dev.mydomain.com ProxyRequests Off RequestHeader set Host %{HOST}s RequestHeader set X-Real-IP %{REMOTE_ADDR}s RequestHeader set X-Forwarded-For %{REMOTE_ADDR}s RequestHeader set X-Forwarded-Host %{SERVER_NAME}s ProxyPass / http://1.2.3.4:8888/ ProxyPassReverse / http://1.2.3.4:8888/
注:xxx、yyy、somesite-dev及mydomain.com均为脱敏内容,应用在VS调试器中运行正常,且已清理企业应用中其他回调地址,仅保留上述地址。
更新1:redirect_uri非空但不匹配
调整httpd配置后,redirect_uri不再为空,但出现新错误:
AADSTS50011: 请求中指定的重定向URI 'https://1.2.3.4:8888/signin-oidc'与应用'yyy'配置的重定向URI不匹配。
更新后的httpd配置:
ProxyRequests Off RequestHeader set Host somesite-dev.mydomain.com RequestHeader set X-Real-IP %{REMOTE_ADDR}s RequestHeader set X-Forwarded-For %{REMOTE_ADDR}s RequestHeader set X-Forwarded-Host %{SERVER_NAME}s RequestHeader set X-Forwarded-Proto expr=%{REQUEST_SCHEME} ProxyPass / http://1.2.3.4:8888/ ProxyPassReverse / https://somesite-dev.mydomain.com/
更新2:问题解决
在Program.cs中添加以下配置后,认证流程恢复正常:
builder.Services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, options => { options.Events = new OpenIdConnectEvents { OnRedirectToIdentityProvider = context => { context.ProtocolMessage.RedirectUri = "https://somesite-dev.mydomain.com/signin-oidc"; return Task.CompletedTask; } }; });
内容的提问来源于stack exchange,提问作者Matthew Strickler
相关产品推荐
相关产品推荐

