You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core 6 Web API验证Azure SSO Token后仍返回401错误

问题:React调用ASP.NET Core 6 Web API返回401(Token已验证通过)

我有一套React前端调用ASP.NET Core 6 Web API的系统,已经为两者配置了正确的租户、ClientID等信息。React站点可以正常登录并获取JWT Token,Token本身也没有异常,但向Web API发起POST请求时,始终返回HTTP 401 Unauthorized错误。查看Web API的调试输出,显示Token已经验证完成:

info: Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter[0]
      IDX10245: Creating claims identity from the validated token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.
Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter: Information: IDX10245: Creating claims identity from the validated token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.
info: Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter[0]
      IDX10241: Security token validated. token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.
Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter: Information: IDX10241: Security token validated. token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'.
dbug: Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics[0]
      Begin OnTokenValidatedAsync. 
Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics: Debug: Begin OnTokenValidatedAsync. 
dbug: Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics[0]
      End OnTokenValidatedAsync. 

尽管Token验证通过,Web API还是返回401错误。我已经排查过中间件配置顺序,确认app.UseAuthentication()和app.UseAuthorization()的位置正确:

var app = builder.Build();

app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();

app.UseCors(
    MyAllowSpecificOrigins
);

app.UseAuthentication();
app.UseAuthorization();

app.MapControllers();

app.Run();

React配置信息(已脱敏)

REACT_APP_CLIENT_ID=11111111-1111-1111-11111-111111111111
REACT_APP_AUTHORITY=<microsoftloginurl>/22222222-2222-2222-2222-222222222222
REACT_APP_REDIRECT_URL=<localhost>:3000
REACT_APP_API_URL=<localhost>:7145/api

Web API配置信息(已脱敏)

"AzureAd": {
    "Instance": "<microsoftloginurl>",
    "Domain": "my.domain",
    "TenantId": "11111111-1111-1111-11111-111111111111",
    "ClientId": "22222222-2222-2222-2222-222222222222",
    "CallbackPath": "/signin-oidc"
},

排查解决方案

  • 检查API权限声明:确认Web API的控制器/Action上的[Authorize]属性是否附带了特定角色或范围要求。如果API需要scope或role声明,而React获取的Token中没有包含对应内容,会触发401。
  • 验证Token受众(Audience):检查JWT的aud字段是否与Web API的ClientID一致。React请求Token时,必须将Web API的ClientID作为scope的一部分(例如api://<WebAPI_ClientID>/access_as_user),否则Token的受众会指向React自身的ClientID,被Web API拒绝。
  • 完善CORS配置:确保Web API的CORS策略启用了允许携带凭证(AllowCredentials()),同时React请求时设置withCredentials: true,否则Token可能无法正确传递到API。
  • 开启PII日志:在Web API的Program.cs中添加IdentityModelEventSource.ShowPII = true;,可以查看Token的完整声明内容,确认是否缺少必要的权限信息。
  • 确认Token有效性:检查请求时携带的Token是否未过期,可以通过解码Token查看exp字段。
  • 检查认证服务注册:确保Web API正确注册了Microsoft Identity Web服务,即调用了builder.Services.AddMicrosoftIdentityWebApiAuthentication(builder.Configuration);,这是Token验证的基础配置。

内容的提问来源于stack exchange,提问作者Matthew Cammarata

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 10:32:28