.NET 7应用WS-Federation未调用ADFS身份验证问题排查
本人是.NET Core新手,公司正将新应用迁移至.NET 7,但该应用未尝试调用ADFS(用于SSO单点登录)。已验证WS-Federation元数据和wtrealm正确,且ADFS已按对应配置完成设置,以下是Program文件代码:
using Microsoft.AspNetCore.Authentication.Cookies; using Microsoft.AspNetCore.Authentication.WsFederation; using Microsoft.AspNetCore.Cors.Infrastructure; using Microsoft.AspNetCore.Identity; using Microsoft.AspNetCore.OData; using Microsoft.EntityFrameworkCore; var builder = WebApplication.CreateBuilder(args); builder.Configuration.AddJsonFile("appsettings.json"); builder.Services.AddControllers().AddOData( options => options.Select().Filter().OrderBy().Expand().Count().SetMaxTop(null) ); builder.Services.Configure<GlobalAppSettings.ConnectionString>(builder.Configuration.GetSection("ConnectionStrings")); builder.Services.Configure<GlobalAppSettings.AppEnvironment>(builder.Configuration.GetSection("AppSettings")); builder.Services.AddAuthentication(sharedOptions => { sharedOptions.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; sharedOptions.DefaultChallengeScheme = WsFederationDefaults.AuthenticationScheme; }) .AddWsFederation(options => { options.UseTokenLifetime = false; options.Wtrealm = "urn:app"; options.MetadataAddress = "https://sso.app.com/FederationMetadata/2007-06/FederationMetadata.xml"; options.Wreply = "https://localhost:44307/app/"; }) .AddCookie(options => { options.Cookie.Name = "app"; options.Cookie.Path = "/app"; options.SlidingExpiration = true; options.ExpireTimeSpan = new TimeSpan(0, 40, 0); }); builder.Services.AddHttpContextAccessor(); builder.Services.AddDbContext<DBcontext>(options => options.UseSqlServer(builder.Configuration.GetConnectionString("PrimaryConnectionString")!)); builder.Services.AddScoped<Utility>(); builder.Services.AddAutoMapper(AppDomain.CurrentDomain.GetAssemblies()); var app = builder.Build(); // Configure the HTTP request pipeline. app.UsePathBase("/app"); app.UseAuthentication(); app.UseRouting(); app.UseAuthorization(); app.UseEndpoints(configure: endpoints => endpoints.MapControllers()); app.Run();
排查方向及解决方法
添加授权标记触发认证流程
仅配置认证体系但未保护任何资源时,系统不会自动触发ADFS跳转。在需要SSO验证的控制器或Action上添加[Authorize]特性:[Authorize] [ApiController] [Route("api/[controller]")] public class SecureController : ControllerBase { // 受保护的接口逻辑 }校验Wreply与ADFS重定向规则一致性
确认ADFS端的信赖方信任(Relying Party Trust)中,重定向URI完全包含https://localhost:44307/app/,包括端口和路径。本地调试时,确保站点证书被ADFS服务器信任,避免HTTPS证书问题阻止跳转。检查Cookie路径与应用路径的匹配性
当前Cookie路径设置为/app,同时应用使用UsePathBase("/app"),可暂时移除Cookie.Path配置测试,排除路径不匹配导致的认证状态无法维持问题。验证元数据地址的网络可达性
在应用服务器上测试能否访问ADFS元数据地址https://sso.app.com/FederationMetadata/2007-06/FederationMetadata.xml,排查防火墙、代理等网络拦截问题。添加调试日志追踪认证流程
在WsFederation配置中添加事件日志,同时调整应用日志级别,确认认证流程是否触发:.AddWsFederation(options => { // 原有配置... options.Events = new WsFederationEvents { OnRedirectToIdentityProvider = context => { Console.WriteLine("触发ADFS跳转请求"); return Task.CompletedTask; }, OnAuthenticationFailed = context => { Console.WriteLine($"认证失败原因: {context.Exception.Message}"); return Task.CompletedTask; } }; })在appsettings.json中开启调试日志:
"Logging": { "LogLevel": { "Microsoft.AspNetCore.Authentication": "Debug" } }
内容的提问来源于stack exchange,提问作者SuperVillainPresident

