You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core MVC授权异常:未登录可直接访问需授权页面

问题描述

我希望用户必须登录后才能访问Privacy页面,但目前授权功能只有在登录并注销一次后才会生效:初次启动Web应用时,直接访问Privacy页面无需登录就能进入,必须先完成一次登录再注销,授权规则才会正常工作。我确定几小时前一切都是正常的。


初始版本Startup.cs

public void ConfigureServices(IServiceCollection services)
{
    //db
    services.AddDbContext<TheAppContext>(options => options.UseSqlServer(Configuration.GetConnectionString("Myconnection")));
    //auth w/ cookies 
    services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddCookie(options =>
    {
        options.Cookie.Name = "MySessionCookie";
        options.LoginPath = "/LogUsers/Expired";
        options.SlidingExpiration = true;
    });
    //service 3/default
    services.AddControllersWithViews();
}

// This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }
    else
    {
        app.UseExceptionHandler("/Home/Error");
        // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
        app.UseHsts();
    }

    app.UseHttpsRedirection();
    app.UseStaticFiles();
    app.UseAuthentication();

    app.UseRouting();

    var cookiePolicyOptions = new CookiePolicyOptions
    {
        MinimumSameSitePolicy = SameSiteMode.Strict,
        HttpOnly = Microsoft.AspNetCore.CookiePolicy.HttpOnlyPolicy.Always,
        Secure = CookieSecurePolicy.None,
    };
    app.UseCookiePolicy(cookiePolicyOptions);

    app.UseAuthorization();

    app.UseEndpoints(endpoints =>
    {
        endpoints.MapControllerRoute(
            name: "default",
            pattern: "{controller=Home}/{action=Index}/{id?}");
    });
}

登录与注销控制器方法

[AllowAnonymous]
[HttpPost]
public async Task<IActionResult> Login(Users login) //login users
{

    if(IsValidUser(login.Username, login.Password))
    {
        var claims = new List<Claim>
        {
            new Claim(ClaimTypes.Name, login.Username),
            new Claim(ClaimTypes.Role, "User"),
        };

        var claimsIdentity = new ClaimsIdentity(claims, CookieAuthenticationDefaults.AuthenticationScheme);

        var authProperties = new AuthenticationProperties
        {
            //The time at which the authentication ticket expires.
            //ExpiresUtc = DateTime.Now.AddMinutes(60),
        };
        
        await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme,
        new ClaimsPrincipal(claimsIdentity),
        authProperties);

        DisplayedUsername = "@" + login.Username;
        CanUserLogout = 1;

        return RedirectToAction("Index", "Home");
    }
    else
    {
        ViewBag.message = "Failed to login";
        return View();
    }
}

private bool IsValidUser(string username, string password)
{
    var user = _context.Users.FirstOrDefault(u => u.Username == username && u.Password == password);

    if (user != null)
    {
        return true;
    }
    
    return false;
}

[Authorize]
public async Task<ActionResult> Logout()
{
    await HttpContext.SignOutAsync(
        CookieAuthenticationDefaults.AuthenticationScheme);
    CanUserLogout = 0;
    return RedirectToAction("Login", "Logusers");
}

Home控制器的Privacy方法

[Authorize]
public IActionResult Privacy()
{
    return View();
}

编辑1 - 更新后的Startup.cs

public class Startup
{
    public Startup(IConfiguration configuration)
    {
        Configuration = configuration;
    }

    public IConfiguration Configuration { get; }

    // This method gets called by the runtime. Use this method to add services to the container.
    public void ConfigureServices(IServiceCollection services)
    {
        //db
        services.AddDbContext<TheAppContext>(options => options.UseSqlServer(Configuration.GetConnectionString("Myconnection")));
        //auth w/ cookies 
        services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
        .AddCookie(options =>
        {
            options.Cookie.Name = "MySessionCookie";
            options.LoginPath = "/LogUsers/Expired";
            options.SlidingExpiration = true;
        });

        //service 3/default
        services.AddControllersWithViews();
    }

    // This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
    public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
    {
        if (env.IsDevelopment())
        {
            app.UseDeveloperExceptionPage();
        }
        else
        {
            app.UseExceptionHandler("/Home/Error");
            // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
            app.UseHsts();
        }

        app.UseHttpsRedirection();
        app.UseStaticFiles();

        var cookiePolicyOptions = new CookiePolicyOptions
        {
            MinimumSameSitePolicy = SameSiteMode.Strict,
            HttpOnly = Microsoft.AspNetCore.CookiePolicy.HttpOnlyPolicy.Always,
            Secure = CookieSecurePolicy.None,
        };

        app.UseCookiePolicy(cookiePolicyOptions);

        app.UseAuthentication();

        app.UseRouting();

        app.UseAuthorization();

        app.UseEndpoints(endpoints =>
        {
            endpoints.MapControllerRoute(
                name: "default",
                pattern: "{controller=Home}/{action=Index}/{id?}");
        });
    }
}

感谢任何形式的帮助。


内容的提问来源于stack exchange,提问作者Tutorial Hell Veteran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 16:48:10