You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 7应用WS-Federation未调用ADFS身份验证问题排查

.NET 7 应用未触发ADFS SSO排查方案

本人是.NET Core新手,公司正将新应用迁移至.NET 7,但该应用未尝试调用ADFS(用于SSO单点登录)。已验证WS-Federation元数据和wtrealm正确,且ADFS已按对应配置完成设置,以下是Program文件代码:

using Microsoft.AspNetCore.Authentication.Cookies;
using Microsoft.AspNetCore.Authentication.WsFederation;
using Microsoft.AspNetCore.Cors.Infrastructure;
using Microsoft.AspNetCore.Identity;
using Microsoft.AspNetCore.OData;
using Microsoft.EntityFrameworkCore;

var builder = WebApplication.CreateBuilder(args);

builder.Configuration.AddJsonFile("appsettings.json");

builder.Services.AddControllers().AddOData(
    options => options.Select().Filter().OrderBy().Expand().Count().SetMaxTop(null)
);
builder.Services.Configure<GlobalAppSettings.ConnectionString>(builder.Configuration.GetSection("ConnectionStrings"));
builder.Services.Configure<GlobalAppSettings.AppEnvironment>(builder.Configuration.GetSection("AppSettings"));


builder.Services.AddAuthentication(sharedOptions =>
    {
        sharedOptions.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        sharedOptions.DefaultChallengeScheme = WsFederationDefaults.AuthenticationScheme;
    })

    .AddWsFederation(options =>
    {
        options.UseTokenLifetime = false;
        options.Wtrealm = "urn:app";
        options.MetadataAddress = "https://sso.app.com/FederationMetadata/2007-06/FederationMetadata.xml";
        options.Wreply = "https://localhost:44307/app/";

    })
    .AddCookie(options =>
    {
        options.Cookie.Name = "app";
        options.Cookie.Path = "/app";
        options.SlidingExpiration = true;
        options.ExpireTimeSpan = new TimeSpan(0, 40, 0);
    });

builder.Services.AddHttpContextAccessor();
builder.Services.AddDbContext<DBcontext>(options => options.UseSqlServer(builder.Configuration.GetConnectionString("PrimaryConnectionString")!));
builder.Services.AddScoped<Utility>();

builder.Services.AddAutoMapper(AppDomain.CurrentDomain.GetAssemblies());

var app = builder.Build();

// Configure the HTTP request pipeline.
app.UsePathBase("/app");


app.UseAuthentication();

app.UseRouting();
app.UseAuthorization();
app.UseEndpoints(configure: endpoints => endpoints.MapControllers());


app.Run();

排查方向及解决方法

  • 添加授权标记触发认证流程
    仅配置认证体系但未保护任何资源时,系统不会自动触发ADFS跳转。在需要SSO验证的控制器或Action上添加[Authorize]特性:

    [Authorize]
    [ApiController]
    [Route("api/[controller]")]
    public class SecureController : ControllerBase
    {
        // 受保护的接口逻辑
    }
    
  • 校验Wreply与ADFS重定向规则一致性
    确认ADFS端的信赖方信任(Relying Party Trust)中,重定向URI完全包含https://localhost:44307/app/,包括端口和路径。本地调试时,确保站点证书被ADFS服务器信任,避免HTTPS证书问题阻止跳转。

  • 检查Cookie路径与应用路径的匹配性
    当前Cookie路径设置为/app,同时应用使用UsePathBase("/app"),可暂时移除Cookie.Path配置测试,排除路径不匹配导致的认证状态无法维持问题。

  • 验证元数据地址的网络可达性
    在应用服务器上测试能否访问ADFS元数据地址https://sso.app.com/FederationMetadata/2007-06/FederationMetadata.xml,排查防火墙、代理等网络拦截问题。

  • 添加调试日志追踪认证流程
    在WsFederation配置中添加事件日志,同时调整应用日志级别,确认认证流程是否触发:

    .AddWsFederation(options =>
    {
        // 原有配置...
        options.Events = new WsFederationEvents
        {
            OnRedirectToIdentityProvider = context =>
            {
                Console.WriteLine("触发ADFS跳转请求");
                return Task.CompletedTask;
            },
            OnAuthenticationFailed = context =>
            {
                Console.WriteLine($"认证失败原因: {context.Exception.Message}");
                return Task.CompletedTask;
            }
        };
    })
    

    在appsettings.json中开启调试日志:

    "Logging": {
        "LogLevel": {
            "Microsoft.AspNetCore.Authentication": "Debug"
        }
    }
    

内容的提问来源于stack exchange,提问作者SuperVillainPresident

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 13:13:22