You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置基于.NET Framework 4.7.1的MVC客户端以对接基于.NET Core的IdentityServer4 (3.1)实现身份认证

Configuring .NET Framework 4.7.1 MVC Client for IdentityServer4 3.1

I totally get where you're coming from—you've nailed the .NET Core + IdentityServer4 setup, but the .NET Framework MVC client feels like a whole different workflow. No worries, we can replicate that exact configuration using OWIN middleware, the standard for authentication in .NET Framework web apps. Here's how to do it step by step:

1. Install Required NuGet Packages

First, add these packages to your MVC project (use the Package Manager Console or NuGet Package Manager):

  • Microsoft.Owin.Security.Cookies (handles cookie-based session management)
  • Microsoft.Owin.Security.OpenIdConnect (implements OpenID Connect for IdentityServer4)
  • Microsoft.Owin.Host.SystemWeb (integrates OWIN with IIS for ASP.NET MVC)

2. Create/Update the OWIN Startup Class

If your project doesn't have an OWIN Startup class yet, add one (right-click project → Add → Class → search for "OWIN Startup Class"). Then configure the authentication middleware to match your .NET Core setup:

using Microsoft.Owin;
using Owin;
using System.IdentityModel.Tokens.Jwt;
using Microsoft.Owin.Security;
using Microsoft.Owin.Security.Cookies;
using Microsoft.Owin.Security.OpenIdConnect;

[assembly: OwinStartup(typeof(YourMvcProjectNamespace.Startup))]
namespace YourMvcProjectNamespace
{
    public class Startup
    {
        public void Configuration(IAppBuilder app)
        {
            // Disable default claim mapping (matches JwtSecurityTokenHandler.DefaultMapInboundClaims = false in .NET Core)
            JwtSecurityTokenHandler.DefaultMapInboundClaims = false;

            // Configure cookie authentication (equivalent to AddCookie("Cookies") in .NET Core)
            app.UseCookieAuthentication(new CookieAuthenticationOptions
            {
                AuthenticationType = "Cookies"
            });

            // Configure OpenID Connect (equivalent to AddOpenIdConnect("oidc", ...) in .NET Core)
            app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
            {
                AuthenticationType = "oidc",
                SignInAsAuthenticationType = "Cookies", // Links OIDC flow to cookie session persistence

                // Core settings matching your .NET Core config
                Authority = "https://myIdentityServer:4532",
                ClientId = "MVC_Net_Framework",
                ClientSecret = "mysecret",
                ResponseType = "code", // Uses Authorization Code flow, same as .NET Core

                // Scopes and token persistence
                Scope = { "openid", "profile", "myScope" }, // Include required default scopes + your custom scope
                SaveTokens = true, // Persists access/refresh tokens in the cookie, same as .NET Core

                // Callback paths (must match what's configured in IdentityServer4 for your client)
                RedirectUri = "https://your-mvc-client-url/signin-oidc",
                PostLogoutRedirectUri = "https://your-mvc-client-url/signout-callback-oidc"
            });
        }
    }
}

3. Map .NET Core Config to .NET Framework Equivalents

Let’s break down how this aligns with your original .NET Core code:

  • JwtSecurityTokenHandler.DefaultMapInboundClaims = false: Same exact line—prevents Microsoft’s default claim mapping from altering the claims sent by IdentityServer4.
  • options.DefaultScheme = "Cookies" / options.DefaultChallengeScheme = "oidc": In OWIN, this is handled by setting SignInAsAuthenticationType = "Cookies" on the OpenID Connect options, which ties the OIDC flow to the cookie middleware for session storage.
  • AddCookie("Cookies"): Directly maps to app.UseCookieAuthentication with AuthenticationType = "Cookies".
  • AddOpenIdConnect settings: All core properties like Authority, ClientId, ClientSecret, ResponseType, Scope, and SaveTokens are mirrored here.

4. Update IdentityServer4 Client Configuration

Make sure your IdentityServer4 client definition (in your .NET Core IdentityServer project) includes these settings for your .NET Framework client:

new Client
{
    ClientId = "MVC_Net_Framework",
    ClientName = ".NET Framework MVC Client",
    ClientSecrets = { new Secret("mysecret".Sha256()) },

    AllowedGrantTypes = GrantTypes.Code,
    RedirectUris = { "https://your-mvc-client-url/signin-oidc" },
    PostLogoutRedirectUris = { "https://your-mvc-client-url/signout-callback-oidc" },
    AllowedScopes = { "openid", "profile", "myScope" },

    AllowOfflineAccess = true // Only enable if you need refresh tokens
}

5. Secure Your MVC Controllers

Just like in .NET Core, add the [Authorize] attribute to controllers/actions you want to protect:

[Authorize]
public class SecureController : Controller
{
    public ActionResult Index()
    {
        // Access user claims or tokens here
        var accessToken = HttpContext.GetOwinContext().Authentication.GetTokenAsync("access_token").Result;
        return View();
    }
}

That’s it! This setup will mirror the behavior of your .NET Core client—users will be redirected to IdentityServer4 for login, and the MVC app will use cookies to maintain the session, with access tokens stored if needed.

内容的提问来源于stack exchange,提问作者Red

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.29 11:23:38