You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 6 Linux应用Azure AD认证redirect_uri异常问题排查

反向代理下.NET 6应用Azure AD认证redirect_uri问题排查与解决

问题背景

部署在httpd反向代理后的.NET 6 Linux应用,重定向到Azure进行认证时触发错误:

AADSTS90102: 'redirect_uri'值必须是有效的绝对URI,请求中的redirect_uri为http%3A%2F%2F%28null%29%2Fsignin-oidc。

相关配置

Program.cs

// Add services to the container.
builder.Services.AddAuthentication(OpenIdConnectDefaults.AuthenticationScheme)
    .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAd"));

builder.Services.AddAuthorization(options =>
{
    // By default, all incoming requests will be authorized according to the default policy.
    options.FallbackPolicy = options.DefaultPolicy;
});
builder.Services.AddRazorPages()
    .AddMicrosoftIdentityUI();

var app = builder.Build();

// Configure the HTTP request pipeline.
if (!app.Environment.IsDevelopment())
{
    app.UseExceptionHandler("/Error");
    // The default HSTS value is 30 days. You may want to change this for production scenarios.
    app.UseHsts();
}

app.UseForwardedHeaders();

app.UseHttpsRedirection();
app.UseStaticFiles();

app.UseRouting();

app.UseSession();
app.UseAuthentication();
app.UseAuthorization();

app.MapRazorPages();
app.MapControllers();

app.Run();

appsettings.json

"AzureAd": {
    "Instance": "https://login.microsoftonline.com/",
    "Domain": "mydomain.com",
    "TenantId": "xxx",
    "ClientId": "yyy",
    "CallbackPath": "/signin-oidc"
}

企业应用回调URL

已配置的回调URL为:https://somesite-dev.mydomain.com/signin-oidc

初始httpd配置

ServerName somesite-dev.mydomain.com

ProxyRequests Off
RequestHeader set Host %{HOST}s
RequestHeader set X-Real-IP %{REMOTE_ADDR}s
RequestHeader set X-Forwarded-For %{REMOTE_ADDR}s
RequestHeader set X-Forwarded-Host %{SERVER_NAME}s
ProxyPass / http://1.2.3.4:8888/
ProxyPassReverse / http://1.2.3.4:8888/

注:xxx、yyy、somesite-dev及mydomain.com均为脱敏内容,应用在VS调试器中运行正常,且已清理企业应用中其他回调地址,仅保留上述地址。


更新1:redirect_uri非空但不匹配

调整httpd配置后,redirect_uri不再为空,但出现新错误:

AADSTS50011: 请求中指定的重定向URI 'https://1.2.3.4:8888/signin-oidc'与应用'yyy'配置的重定向URI不匹配。

更新后的httpd配置:

ProxyRequests Off
RequestHeader set Host somesite-dev.mydomain.com
RequestHeader set X-Real-IP %{REMOTE_ADDR}s
RequestHeader set X-Forwarded-For %{REMOTE_ADDR}s
RequestHeader set X-Forwarded-Host %{SERVER_NAME}s
RequestHeader set X-Forwarded-Proto expr=%{REQUEST_SCHEME}
ProxyPass / http://1.2.3.4:8888/
ProxyPassReverse / https://somesite-dev.mydomain.com/

更新2:问题解决

在Program.cs中添加以下配置后,认证流程恢复正常:

builder.Services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, options =>
{
    options.Events = new OpenIdConnectEvents
    {
        OnRedirectToIdentityProvider = context =>
        {
            context.ProtocolMessage.RedirectUri = "https://somesite-dev.mydomain.com/signin-oidc";
            return Task.CompletedTask;
        }
    };
});

内容的提问来源于stack exchange,提问作者Matthew Strickler

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 18:20:14