You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET 7 Web应用Google SSO登出异常求助(含组件更换后新问题)

解决方案:.NET 7 Google 应用级登出实现

针对你遇到的问题,以下是两种组件对应的解决方案,核心思路是清除本应用的登录Cookie,并强制下次登录时要求用户重新输入凭证,同时避免触发Google全局会话登出:

方案一:使用原生 Microsoft.AspNetCore.Authentication.Google

由于GoogleHandler本身不支持SignOutAsync,我们需要通过以下步骤实现需求:

  1. 配置Google认证(保持基础配置即可):
builder.Services.AddAuthentication()
    .AddGoogle(options =>
    {
        options.ClientId = builder.Configuration["Authentication:Google:ClientId"];
        options.ClientSecret = builder.Configuration["Authentication:Google:ClientSecret"];
    })
    .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme);
  1. 实现登出逻辑:
    清除本应用的Cookie会话,并重定向到带prompt=login参数的Google授权页面,强制用户重新输入凭证:
public async Task<IActionResult> Logout()
{
    // 清除本应用的登录Cookie
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);

    // 构造带强制登录参数的Google授权URL
    var clientId = builder.Configuration["Authentication:Google:ClientId"];
    var redirectUri = Url.Action("GoogleResponse", "Account", null, Request.Scheme);
    var authUrl = $"https://accounts.google.com/o/oauth2/v2/auth?client_id={Uri.EscapeDataString(clientId)}" +
                  $"&redirect_uri={Uri.EscapeDataString(redirectUri)}" +
                  "&response_type=code&scope=openid%20email%20profile&prompt=login";

    return Redirect(authUrl);
}
  • prompt=login 参数会让Google强制用户输入账号密码,即使存在活跃的全局会话,确保本应用的登录状态完全重置,但不影响Gmail等其他Google应用的使用。

方案二:使用 Google.Apis.Auth.AspNetCore3

针对你遇到的Cannot redirect to the end session endpoint错误,只需禁用全局登出重定向,同时配置登录强制验证:

  1. 配置Google OpenID Connect:
builder.Services.AddAuthentication()
    .AddGoogleOpenIdConnect(options =>
    {
        options.ClientId = builder.Configuration["Authentication:Google:ClientId"];
        options.ClientSecret = builder.Configuration["Authentication:Google:ClientSecret"];

        // 拦截全局登出重定向,避免触发Google全局会话退出
        options.Events.OnRedirectToEndSessionEndpoint = context =>
        {
            context.Response.Redirect("/Account/Login");
            return Task.CompletedTask;
        };

        // 登录时强制要求重新输入凭证
        options.Events.OnRedirectToAuthorizationEndpoint = context =>
        {
            context.RedirectUri += "&prompt=login";
            return Task.CompletedTask;
        };
    })
    .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme);
  1. 实现登出逻辑:
    只需清除本地Cookie会话即可:
public async Task<IActionResult> Logout()
{
    await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
    return RedirectToAction("Login", "Account");
}

关键说明

  • 两种方案的核心都是仅清除本应用的登录状态,通过prompt=login参数强制用户重新验证身份,而非退出Google全局会话。
  • 避免调用Google认证方案的SignOutAsync,因为Google的OAuth2流程本身不支持应用级的登出端点,原生组件也未实现该功能。

内容的提问来源于stack exchange,提问作者nl-x

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 21:50:27