Jwt Bearer Authentication中间件始终将User.Identity.IsAuthenticated置为false问题求助
排查JWT验证后
IsAuthenticated始终为false的问题 我来帮你一步步定位问题,从你的代码里能看到几个关键的不一致和缺失配置,这应该就是导致验证失败的核心原因:
1. SecretKey处理逻辑完全不匹配
这是最致命的问题!你生成Token和验证Token时对SecretKey的处理方式完全不同:
- 生成Token时:
byte[] key = Convert.FromBase64String(secretKey);(对密钥做Base64解码) - 验证时:
IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(secretkey));(直接把密钥字符串转成UTF-8字节)
这意味着你用Base64解码后的密钥生成了签名,但验证时却用原始字符串的UTF-8字节作为密钥,两者肯定不匹配,签名验证直接失败,自然IsAuthenticated会是false。
修复方式:统一两边的密钥处理逻辑,比如都使用Base64解码:
// 在MyJwtAuthenticationOptions中修改密钥处理逻辑 var secretkey = ConfigurationManager.AppSettings["SecretKey"].ToString(); byte[] keyBytes = Convert.FromBase64String(secretkey); // 和生成Token时保持一致 TokenValidationParameters = new TokenValidationParameters() { ValidateIssuerSigningKey = true, IssuerSigningKey = new SymmetricSecurityKey(keyBytes), ValidAlgorithms = new string[] { SecurityAlgorithms.HmacSha256Signature } };
2. TokenValidationParameters缺少必要的验证开关
你的Token生成逻辑里没有设置Issuer(发行人)和Audience(受众),但TokenValidationParameters默认是开启这两项验证的(ValidateIssuer和ValidateAudience默认值为true),这会导致验证时因为找不到匹配的Issuer/Audience而失败。
修复方式:在TokenValidationParameters中关闭不需要的验证项:
TokenValidationParameters = new TokenValidationParameters() { ValidateIssuerSigningKey = true, IssuerSigningKey = new SymmetricSecurityKey(keyBytes), ValidAlgorithms = new string[] { SecurityAlgorithms.HmacSha256Signature }, ValidateIssuer = false, // 关闭发行人验证(如果你的业务不需要的话) ValidateAudience = false, // 关闭受众验证(如果你的业务不需要的话) ValidateLifetime = true // 保留过期时间验证,这是必要的安全逻辑 };
3. 统一AuthenticationType(可选但建议)
虽然你在生成ClaimsIdentity和JwtBearerAuthenticationOptions里都设置了AuthenticationType = "Basic",但JWT Bearer认证通常用"Bearer"作为AuthenticationType,这样和请求头的Bearer前缀更匹配,避免潜在的混淆。
修改建议:
// 在MyJwtAuthenticationOptions中修改 AuthenticationType = "Bearer"; // 在生成Token的ClaimsIdentity中修改 Subject = new ClaimsIdentity(new[] { new Claim("UserId", userid)}, "Bearer"),
4. 最后确认两个细节
- 你的中间件顺序是正确的:
UseJwtBearerAuthentication→UseAutofacMiddleware→Use<ReadBodyMiddleware>→UseWebApi,确保JWT验证在WebApi处理请求前执行。 - 检查Postman的请求头:确认Authorization头格式是
Bearer {你的Token},没有多余空格或拼写错误。
做完这些修改后,再测试应该就能让HttpContext.Current.User.Identity.IsAuthenticated变为true了。
内容的提问来源于stack exchange,提问作者Abolfazl
相关产品推荐
相关产品推荐

