ASP.NET Core 6 Web API验证Azure SSO Token后仍返回401错误
问题:React调用ASP.NET Core 6 Web API返回401(Token已验证通过)
我有一套React前端调用ASP.NET Core 6 Web API的系统,已经为两者配置了正确的租户、ClientID等信息。React站点可以正常登录并获取JWT Token,Token本身也没有异常,但向Web API发起POST请求时,始终返回HTTP 401 Unauthorized错误。查看Web API的调试输出,显示Token已经验证完成:
info: Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter[0] IDX10245: Creating claims identity from the validated token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'. Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter: Information: IDX10245: Creating claims identity from the validated token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'. info: Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter[0] IDX10241: Security token validated. token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'. Microsoft.IdentityModel.LoggingExtensions.IdentityLoggerAdapter: Information: IDX10241: Security token validated. token: '[PII of type 'System.IdentityModel.Tokens.Jwt.JwtSecurityToken' is hidden. For more details, see https://aka.ms/IdentityModel/PII.]'. dbug: Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics[0] Begin OnTokenValidatedAsync. Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics: Debug: Begin OnTokenValidatedAsync. dbug: Microsoft.Identity.Web.Resource.JwtBearerMiddlewareDiagnostics[0] End OnTokenValidatedAsync.
尽管Token验证通过,Web API还是返回401错误。我已经排查过中间件配置顺序,确认app.UseAuthentication()和app.UseAuthorization()的位置正确:
var app = builder.Build(); app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseCors( MyAllowSpecificOrigins ); app.UseAuthentication(); app.UseAuthorization(); app.MapControllers(); app.Run();
React配置信息(已脱敏)
REACT_APP_CLIENT_ID=11111111-1111-1111-11111-111111111111 REACT_APP_AUTHORITY=<microsoftloginurl>/22222222-2222-2222-2222-222222222222 REACT_APP_REDIRECT_URL=<localhost>:3000 REACT_APP_API_URL=<localhost>:7145/api
Web API配置信息(已脱敏)
"AzureAd": { "Instance": "<microsoftloginurl>", "Domain": "my.domain", "TenantId": "11111111-1111-1111-11111-111111111111", "ClientId": "22222222-2222-2222-2222-222222222222", "CallbackPath": "/signin-oidc" },
排查解决方案
- 检查API权限声明:确认Web API的控制器/Action上的
[Authorize]属性是否附带了特定角色或范围要求。如果API需要scope或role声明,而React获取的Token中没有包含对应内容,会触发401。 - 验证Token受众(Audience):检查JWT的
aud字段是否与Web API的ClientID一致。React请求Token时,必须将Web API的ClientID作为scope的一部分(例如api://<WebAPI_ClientID>/access_as_user),否则Token的受众会指向React自身的ClientID,被Web API拒绝。 - 完善CORS配置:确保Web API的CORS策略启用了允许携带凭证(
AllowCredentials()),同时React请求时设置withCredentials: true,否则Token可能无法正确传递到API。 - 开启PII日志:在Web API的
Program.cs中添加IdentityModelEventSource.ShowPII = true;,可以查看Token的完整声明内容,确认是否缺少必要的权限信息。 - 确认Token有效性:检查请求时携带的Token是否未过期,可以通过解码Token查看
exp字段。 - 检查认证服务注册:确保Web API正确注册了Microsoft Identity Web服务,即调用了
builder.Services.AddMicrosoftIdentityWebApiAuthentication(builder.Configuration);,这是Token验证的基础配置。
内容的提问来源于stack exchange,提问作者Matthew Cammarata
相关产品推荐
相关产品推荐

