You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在ASP.NET Core MVC中添加多套OpenIdConnect认证方案并运行时选择

多Azure AD配置运行时选择登录方案的实现方案

你的需求完全可行,但现有写法存在两个关键问题:重复调用AddAuthentication会覆盖之前的配置,且两个Azure AD配置的CallbackPath相同会导致回调冲突。以下是正确的实现步骤:

1. 调整配置文件

每个Azure AD配置的CallbackPath必须唯一,避免回调路径冲突:

"AzureAd1": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "mydomain1.com",
  "ClientId": "X1",
  "TenantId": "Y1",
  "CallbackPath": "/signin-oidc-1"
},
"AzureAd2": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "mydomain2.com",
  "ClientId": "X2",
  "TenantId": "Y2",
  "CallbackPath": "/signin-oidc-2"
}

2. 注册多套认证方案

不要重复调用AddAuthentication,而是在同一个认证服务注册中添加多个OpenID Connect方案,每个方案使用唯一的名称:

public void ConfigureServices(IServiceCollection services)
{
    services.AddControllersWithViews();

    // 注册认证服务,不设置默认方案(或按需指定)
    services.AddAuthentication()
        // 注册第一个Azure AD方案,指定唯一方案名"AzureAD1"
        .AddMicrosoftIdentityWebApp(options =>
        {
            Configuration.Bind("AzureAd1", options);
        }, authenticationScheme: "AzureAD1", cookieSchemeName: "CookieAuth")
        // 注册第二个Azure AD方案,指定唯一方案名"AzureAD2"
        .AddMicrosoftIdentityWebApp(options =>
        {
            Configuration.Bind("AzureAd2", options);
        }, authenticationScheme: "AzureAD2", cookieSchemeName: "CookieAuth");

    services.AddAuthorization();
}

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }
    else
    {
        app.UseExceptionHandler("/Home/Error");
        app.UseHsts();
    }

    app.UseHttpsRedirection();
    app.UseStaticFiles();

    app.UseRouting();

    // 必须启用认证和授权中间件
    app.UseAuthentication();
    app.UseAuthorization();

    app.UseEndpoints(endpoints =>
    {
        endpoints.MapControllerRoute(
            name: "default",
            pattern: "{controller=Home}/{action=Index}/{id?}");
    });
}

注:cookieSchemeName可以设置为相同值,实现不同Azure AD登录后共享Cookie会话;若需要隔离会话,可设置不同名称。

3. 运行时选择认证方案

修改Login方法,允许匿名访问(否则未登录用户无法进入该方法),根据参数选择对应方案发起认证挑战:

[AllowAnonymous]
public IActionResult Login(string returnUrl, string x)
{
    // 根据业务逻辑获取x对应的认证方案
    string targetScheme = x switch
    {
        "tenant1" => "AzureAD1",
        "tenant2" => "AzureAD2",
        _ => "AzureAD1" // 默认方案
    };

    // 发起指定方案的认证挑战,登录成功后跳转至returnUrl
    return Challenge(new AuthenticationProperties 
    { 
        RedirectUri = string.IsNullOrEmpty(returnUrl) ? "/" : returnUrl 
    }, targetScheme);
}

关键注意事项

  • 唯一方案名:每个Azure AD认证方案必须有唯一的authenticationScheme名称,否则会覆盖之前的配置。
  • 回调路径唯一:CallbackPath不能重复,否则微软身份平台无法正确区分回调请求对应的应用配置。
  • 匿名访问Login:Login方法必须添加[AllowAnonymous],避免未登录用户被重定向到登录页,陷入循环。
  • 无需作用域上下文:通过Challenge方法直接指定认证方案即可实现运行时选择,不需要额外的作用域上下文配置。

内容的提问来源于stack exchange,提问作者Sigmundur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 19:43:14