You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

外部登录后User.Identity.IsAuthenticated为false的异常排查

问题分析与解决方案

问题现象

此前正常运行的Google外部登录功能突然失效:

  • Google登录完成后,回调方法通过LocalRedirect重定向至受保护页面时,User.Identity.IsAuthenticated为false,浏览器被重定向回登录页
  • 手动访问该受保护页面时,User.Identity.IsAuthenticated为true,页面可正常加载
  • 常规账号密码登录功能正常,使用Cookie认证,中间件配置未变更

核心原因

认证配置中默认Scheme设置为JWT(JwtBearerDefaults.AuthenticationScheme),但外部登录(Google)和账号密码登录依赖的是Cookie认证。回调重定向时,系统优先使用默认的JWT Scheme校验,此时Cookie未被该Scheme识别,导致认证状态为false;手动访问时Cookie已写入,Cookie认证Scheme生效,状态恢复正常。

解决方案

1. 修改默认认证Scheme为Cookie

更新Startup.cs中的认证配置,将默认Scheme改为Cookie,同时保留JWT作为可选认证方式:

using Microsoft.AspNetCore.Authentication.Cookies;

// ...

services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddCookie(options =>
    {
        // 可根据需求配置Cookie参数,比如登录路径、过期时间等
        options.LoginPath = "/Security/Login";
    })
    .AddJwtBearer(x =>
    {
        x.RequireHttpsMetadata = true;
        x.SaveToken = true;
        x.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidIssuer = configuration["Modules:Authenticate:AuthJwt:Issuer"],
            ValidateAudience = true,
            ValidAudience = configuration["Modules:Authenticate:AuthJwt:Audience"],
            ValidateIssuerSigningKey = true,
            RequireExpirationTime = false,
            ValidateLifetime = true,
            ClockSkew = TimeSpan.Zero,
            IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(configuration["Modules:Authenticate:AuthJwt:Key"] ?? string.Empty))
        };
    })
    .AddGoogle(googleOptions =>
    {
        googleOptions.ClientId = configuration["Modules:Authenticate:Google:ClientId"] ?? string.Empty;
        googleOptions.ClientSecret = configuration["Modules:Authenticate:Google:ClientSecret"] ?? string.Empty;
        googleOptions.CallbackPath = "/Security/GoogleSignIn";
    });

2. 为JWT认证接口单独指定Scheme

若API接口需要JWT认证,在对应控制器或Action上添加标注:

[Authorize(AuthenticationSchemes = JwtBearerDefaults.AuthenticationScheme)]
public class ApiController : ControllerBase
{
    // ...
}

3. 额外检查项

  • 确认中间件顺序:app.UseAuthentication()必须在app.UseAuthorization()之前,且位于app.UseRouting()之后
  • 检查Cookie的SameSite设置:跨域场景下,需将Cookie的SameSite属性设为SameSiteMode.Lax或SameSiteMode.None(配合HTTPS使用)
  • 验证回调中的SignInAsync操作:确保_signInManager.SignInAsync()执行成功,无异常抛出,且Cookie已正确写入浏览器

内容的提问来源于stack exchange,提问作者jstuardo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.27 21:09:54