You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Asp.Net页面中实现双Azure租户登录按钮的方案示例

实现Asp.Net双独立Azure租户登录方案

1. 配置双租户应用注册参数

在appsettings.json中分别配置两个租户的认证信息,确保回调路径互不冲突:

"AzureAdTenant1": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "tenant1.onmicrosoft.com",
  "TenantId": "{Tenant1唯一GUID}",
  "ClientId": "{租户1应用注册ClientId}",
  "ClientSecret": "{租户1应用注册密钥}",
  "CallbackPath": "/signin-oidc-tenant1"
},
"AzureAdTenant2": {
  "Instance": "https://login.microsoftonline.com/",
  "Domain": "tenant2.onmicrosoft.com",
  "TenantId": "{Tenant2唯一GUID}",
  "ClientId": "{租户2应用注册ClientId}",
  "ClientSecret": "{租户2应用注册密钥}",
  "CallbackPath": "/signin-oidc-tenant2"
}

2. 注册双租户认证服务(Program.cs)

分别为两个租户创建独立的OpenID Connect认证方案,共享Cookie认证保存登录状态:

var builder = WebApplication.CreateBuilder(args);

builder.Services.AddControllersWithViews();

// 注册双租户认证方案
builder.Services.AddAuthentication()
    .AddOpenIdConnect("Tenant1Auth", options =>
    {
        builder.Configuration.Bind("AzureAdTenant1", options);
        options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        options.ResponseType = "code";
        options.SaveTokens = true;
        options.Scope.Add("openid");
        options.Scope.Add("profile");
    })
    .AddOpenIdConnect("Tenant2Auth", options =>
    {
        builder.Configuration.Bind("AzureAdTenant2", options);
        options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
        options.ResponseType = "code";
        options.SaveTokens = true;
        options.Scope.Add("openid");
        options.Scope.Add("profile");
    })
    .AddCookie();

var app = builder.Build();

app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();
app.UseAuthentication();
app.UseAuthorization();

app.MapControllerRoute(
    name: "default",
    pattern: "{controller=Home}/{action=Index}/{id?}");

app.Run();

3. 前端添加租户选择登录按钮

在视图页面(如Index.cshtml)添加两个表单按钮,分别指定对应租户的认证方案:

<div class="login-buttons">
    <form asp-controller="Account" asp-action="Login" method="post">
        <input type="hidden" name="tenantScheme" value="Tenant1Auth" />
        <button type="submit">登录租户1</button>
    </form>
    <form asp-controller="Account" asp-action="Login" method="post">
        <input type="hidden" name="tenantScheme" value="Tenant2Auth" />
        <button type="submit">登录租户2</button>
    </form>
</div>

4. 实现登录逻辑(AccountController)

创建控制器接收登录请求,根据传入的认证方案触发对应租户的登录流程:

using Microsoft.AspNetCore.Authentication;
using Microsoft.AspNetCore.Mvc;

public class AccountController : Controller
{
    [HttpPost]
    public IActionResult Login(string tenantScheme)
    {
        var redirectUrl = Url.Action("Index", "Home");
        return Challenge(new AuthenticationProperties { RedirectUri = redirectUrl }, tenantScheme);
    }

    [HttpPost]
    public async Task<IActionResult> Logout()
    {
        await HttpContext.SignOutAsync(CookieAuthenticationDefaults.AuthenticationScheme);
        return RedirectToAction("Index", "Home");
    }
}

5. 区分租户用户与权限验证

在需要权限验证的Action中,可通过User.Claims获取租户ID区分用户所属租户:

[Authorize]
public IActionResult SecurePage()
{
    var tenantId = User.FindFirst("tid")?.Value;
    var userName = User.Identity.Name;
    // 根据tenantId做租户专属业务逻辑
    return View();
}

内容的提问来源于stack exchange,提问作者user16857750

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 04:07:33