You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core Web API 7.0集成Google OAuth2.0遇状态无效及跳转问题

解决ASP.NET Core 7 Google OAuth2.0授权的「The oauth state was missing or invalid」问题

核心问题排查与修复

1. 完善Program.cs中的认证配置

你的代码缺少默认认证方案和Cookie认证依赖,Google OAuth需要Cookie存储授权状态(state),同时必须启用认证、授权中间件,修改后代码如下:

var builder = WebApplication.CreateBuilder(args);
var services = builder.Services;
var configuration = builder.Configuration;

var connectionString = configuration.GetConnectionString("DefaultConnection");
services.AddDbContext<DataContext>(options =>
{
    options.UseMySql(connectionString, ServerVersion.AutoDetect(connectionString));
});

// 新增默认认证方案与Cookie认证配置
services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme;
})
.AddCookie() // 启用Cookie认证以存储state
.AddGoogle(googleOptions =>
{
    googleOptions.ClientId = configuration["Authentication:Google:ClientId"];
    googleOptions.ClientSecret = configuration["Authentication:Google:ClientSecret"];
    // 指定回调地址,需与Google控制台配置完全一致
    googleOptions.CallbackPath = "/signin-google";
}); 

builder.Services.RegisterCoreConfiguration(builder.Configuration);
builder.Services.RegisterCoreDependencies();

var app = builder.Build();

// 启用认证、授权中间件(顺序不可调换)
app.UseAuthentication();
app.UseAuthorization();

// 映射Razor Page路由(如果使用Razor Page)
app.MapRazorPages();
// 映射API控制器路由(如果有API控制器)
app.MapControllers();

app.Run();

2. 检查配置文件(appsettings.json)

确保Authentication:Google节点配置正确:

{
  "Authentication": {
    "Google": {
      "ClientId": "你的谷歌客户端ID",
      "ClientSecret": "你的谷歌客户端密钥"
    }
  }
}

3. 验证Google控制台的回调地址

在Google Cloud控制台的Web应用凭证中,授权重定向URI必须与代码中CallbackPath完全一致,本地测试格式为https://localhost:端口号/signin-google,线上部署则替换为实际域名。

4. 优化Razor Page登录触发逻辑

避免硬编码链接,使用ASP.NET Core内置方法触发授权:
在IndexModel中添加登录处理方法:

public async Task<IActionResult> OnGetSignInWithGoogle()
{
    return Challenge(new AuthenticationProperties { RedirectUri = "/" }, GoogleDefaults.AuthenticationScheme);
}

修改页面登录链接:

@page
@model IndexModel
@{
    ViewData["Title"] = "Home page";
}

<div class="text-center">
    <h1 class="display-4">Welcome</h1>
    <strong>Home page of future Tinder Clone Web APP :)</strong>

    <a asp-page="/Index" asp-handler="SignInWithGoogle">Sign In with Google</a>
</div>

5. 关于「谷歌授权图标」

微软官方文档中的图标需自行添加CSS与图标资源,默认不会自动生成,可直接使用Google官方登录按钮样式或自定义UI。

错误原因说明

  • 缺少Cookie认证中间件:Google OAuth生成的state参数会存储在Cookie中,未启用Cookie认证会导致state丢失。
  • 中间件顺序错误:UseAuthentication()必须在UseAuthorization()及路由映射之前调用。
  • 回调地址不匹配:Google返回的回调地址与代码配置不一致,会触发state验证失败。

内容的提问来源于stack exchange,提问作者mykhailo ryzhanovskyi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 01:55:00