You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 8 IISExpress AD组授权报错:未注册身份验证处理程序

问题:ASP.NET Core代码在IIS正常运行,IISExpress下提示认证处理器未注册

以下代码在IIS中可正常运行,但在IISExpress中启动时抛出错误:
InvalidOperationException: No authentication handlers are registered. Did you forget to call AddAuthentication().Add[SomeAuthHandler]("Windows",...)?


相关代码与配置

Program.cs核心代码

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.
builder.Services.AddRazorPages();
builder.Services.AddSingleton<IAuthorizationHandler, CheckAdGroupHandler>();
builder.Services.AddAuthentication(IISDefaults.AuthenticationScheme);

builder.Services.AddAuthorization(options =>
{
    options.AddPolicy("my_policy", policy =>
    {
        policy.Requirements.Add(new CheckAdGroupRequirement("some_ad_group, another_ad_group"));
        policy.AuthenticationSchemes = new List<string>()
        {
            IISDefaults.AuthenticationScheme
        };
    });
});

var app = builder.Build();

// 中间件配置(省略部分代码)
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();

app.MapRazorPages();
app.Run();

CheckAdGroupHandler实现

public class CheckAdGroupHandler: AuthorizationHandler<CheckAdGroupRequirement>
{
    protected override async Task HandleRequirementAsync(AuthorizationHandlerContext context,
        CheckAdGroupRequirement requirement)
    {
        List<string> usersGroups = new List<string>();
        WindowsIdentity windowsIdentity = (WindowsIdentity) context.User.Identity;
       
        using (var ctx = new PrincipalContext(ContextType.Domain))
        using (var user = UserPrincipal.FindByIdentity(ctx, windowsIdentity.Name))
        {
            if (user != null)
            {
                foreach (Principal principal in user.GetGroups())
                {
                    string adGroup = principal.SamAccountName;
                    usersGroups.Add(adGroup);
                }
            }
        }

        foreach (var groupName in requirement.GroupNames)
        {
            if (usersGroups.Contains(groupName))
            {
                context.Succeed(requirement);
            }
        }

        await Task.CompletedTask;
    }
}

CheckAdGroupRequirement实现

public class CheckAdGroupRequirement:IAuthorizationRequirement
{
    public List<string> GroupNames { get; set; }

    public CheckAdGroupRequirement(string groupNames)
    {
        GroupNames = groupNames.Split(',').ToList();
    }
}

页面授权配置

[Authorize(Policy = "my_policy")]
public class IndexModel : PageModel
{
    // 页面逻辑
}

launchSettings.json配置

"iisSettings": {
  "windowsAuthentication": true,
  "anonymousAuthentication": false,
  "iisExpress": {
    "applicationUrl": "http://localhost:64205",
    "sslPort": 44374
  }
}

解决方法

1. 注册Windows认证处理器

问题根源在于仅指定了认证方案,但未注册对应的认证处理器。在ASP.NET Core中,针对Windows认证,需要显式添加对应处理器:

  • ASP.NET Core 8+版本(推荐):使用Negotiate处理器
builder.Services.AddAuthentication(IISDefaults.AuthenticationScheme)
    .AddNegotiate();
  • ASP.NET Core 7及以下版本:使用Windows处理器
builder.Services.AddAuthentication(IISDefaults.AuthenticationScheme)
    .AddWindows();

2. 验证IISExpress配置(可选)

若修改后仍有问题,确认项目.vs\config目录下的applicationhost.config中Windows认证已启用:

<security>
  <authentication>
    <anonymousAuthentication enabled="false" />
    <windowsAuthentication enabled="true" />
  </authentication>
</security>

3. 优化授权处理器的空值判断(可选)

为避免潜在空引用异常,在CheckAdGroupHandler中先校验身份类型:

protected override async Task HandleRequirementAsync(AuthorizationHandlerContext context,
    CheckAdGroupRequirement requirement)
{
    if (context.User.Identity is not WindowsIdentity windowsIdentity)
    {
        return;
    }
    // 后续逻辑不变
}

内容的提问来源于stack exchange,提问作者Nigel B

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 01:09:55