ASP.NET Core MVC授权异常:未登录可直接访问需授权页面
问题描述
我希望用户必须登录后才能访问Privacy页面,但目前授权功能只有在登录并注销一次后才会生效:初次启动Web应用时,直接访问Privacy页面无需登录就能进入,必须先完成一次登录再注销,授权规则才会正常工作。我确定几小时前一切都是正常的。
初始版本Startup.cs
public void ConfigureServices(IServiceCollection services) { //db services.AddDbContext<TheAppContext>(options => options.UseSqlServer(Configuration.GetConnectionString("Myconnection"))); //auth w/ cookies services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme) .AddCookie(options => { options.Cookie.Name = "MySessionCookie"; options.LoginPath = "/LogUsers/Expired"; options.SlidingExpiration = true; }); //service 3/default services.AddControllersWithViews(); } // This method gets called by the runtime. Use this method to configure the HTTP request pipeline. public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } else { app.UseExceptionHandler("/Home/Error"); // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts. app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseAuthentication(); app.UseRouting(); var cookiePolicyOptions = new CookiePolicyOptions { MinimumSameSitePolicy = SameSiteMode.Strict, HttpOnly = Microsoft.AspNetCore.CookiePolicy.HttpOnlyPolicy.Always, Secure = CookieSecurePolicy.None, }; app.UseCookiePolicy(cookiePolicyOptions); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); }); }
登录与注销控制器方法
[AllowAnonymous] [HttpPost] public async Task<IActionResult> Login(Users login) //login users { if(IsValidUser(login.Username, login.Password)) { var claims = new List<Claim> { new Claim(ClaimTypes.Name, login.Username), new Claim(ClaimTypes.Role, "User"), }; var claimsIdentity = new ClaimsIdentity(claims, CookieAuthenticationDefaults.AuthenticationScheme); var authProperties = new AuthenticationProperties { //The time at which the authentication ticket expires. //ExpiresUtc = DateTime.Now.AddMinutes(60), }; await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme, new ClaimsPrincipal(claimsIdentity), authProperties); DisplayedUsername = "@" + login.Username; CanUserLogout = 1; return RedirectToAction("Index", "Home"); } else { ViewBag.message = "Failed to login"; return View(); } } private bool IsValidUser(string username, string password) { var user = _context.Users.FirstOrDefault(u => u.Username == username && u.Password == password); if (user != null) { return true; } return false; } [Authorize] public async Task<ActionResult> Logout() { await HttpContext.SignOutAsync( CookieAuthenticationDefaults.AuthenticationScheme); CanUserLogout = 0; return RedirectToAction("Login", "Logusers"); }
Home控制器的Privacy方法
[Authorize] public IActionResult Privacy() { return View(); }
编辑1 - 更新后的Startup.cs
public class Startup { public Startup(IConfiguration configuration) { Configuration = configuration; } public IConfiguration Configuration { get; } // This method gets called by the runtime. Use this method to add services to the container. public void ConfigureServices(IServiceCollection services) { //db services.AddDbContext<TheAppContext>(options => options.UseSqlServer(Configuration.GetConnectionString("Myconnection"))); //auth w/ cookies services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme) .AddCookie(options => { options.Cookie.Name = "MySessionCookie"; options.LoginPath = "/LogUsers/Expired"; options.SlidingExpiration = true; }); //service 3/default services.AddControllersWithViews(); } // This method gets called by the runtime. Use this method to configure the HTTP request pipeline. public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } else { app.UseExceptionHandler("/Home/Error"); // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts. app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); var cookiePolicyOptions = new CookiePolicyOptions { MinimumSameSitePolicy = SameSiteMode.Strict, HttpOnly = Microsoft.AspNetCore.CookiePolicy.HttpOnlyPolicy.Always, Secure = CookieSecurePolicy.None, }; app.UseCookiePolicy(cookiePolicyOptions); app.UseAuthentication(); app.UseRouting(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}"); }); } }
感谢任何形式的帮助。
内容的提问来源于stack exchange,提问作者Tutorial Hell Veteran
相关产品推荐
相关产品推荐

