Azure App Service认证与Duende Identity Server的403权限问题
问题背景与现象
我们有一个受Duende Identity Server 6保护的.NET 6 Web应用,部署在Azure App Service上运行正常。现在要在Azure App Service前添加Azure App Service认证,强制用户访问前必须通过公司Active Directory(含MFA)验证。
当前Web应用是OIDC客户端,会调用自有凭证存储的Duende OIDC Identity Server。Azure App Service认证对接企业AD已配置生效,用户必须先完成认证才能访问Web应用,但在Duende Identity Server登录后,页面重定向至https://webapp.com/signin-oidc时返回403禁止访问。经测试,拦截该请求并移除User-Agent头后可正常访问,推测和CORS相关。
已尝试的配置
- 在webapp.com上设置Allowed Origins为"*"
- 在Identity Server应用上设置Allowed Origins为"*"
- 在Azure App Service认证设置中添加允许的重定向URL:
https://webapp.com/signin-oidc
疑问
是否还有遗漏的配置或需要考虑的方向?
复现代码(基础ASP.NET 6 MVC)
using System.IdentityModel.Tokens.Jwt; var builder = WebApplication.CreateBuilder(args); // Add services to the container. builder.Services.AddControllersWithViews(); JwtSecurityTokenHandler.DefaultMapInboundClaims = false; builder.Services.AddAuthentication(options => { options.DefaultScheme = "Cookies"; options.DefaultChallengeScheme = "oidc"; }) .AddCookie("Cookies") .AddOpenIdConnect("oidc", options => { options.Authority = "https://our-login-authority-url.com"; options.ClientId = "com.company.app"; options.ClientSecret = "<.. secret ..>"; options.ResponseType = "code"; options.UsePkce = true; options.Scope.Clear(); options.Scope.Add("openid"); options.Scope.Add("profile"); options.Scope.Add("offline_access"); // keeps id_token smaller options.GetClaimsFromUserInfoEndpoint = true; options.SaveTokens = true; }); var app = builder.Build(); // Configure the HTTP request pipeline. if (!app.Environment.IsDevelopment()) { app.UseExceptionHandler("/Home/Error"); // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts. app.UseHsts(); } app.UseHttpsRedirection(); app.UseStaticFiles(); app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); app.MapControllerRoute( name: "default", pattern: "{controller=Home}/{action=Index}/{id?}") .RequireAuthorization(); app.Run();
网络请求信息
POST /signin-oidc请求头
POST /signin-oidc HTTP/1.1 Host: mywebapp.com User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: nl,en-US;q=0.7,en;q=0.3 Accept-Encoding: gzip, deflate, br Content-Type: application/x-www-form-urlencoded Content-Length: 699 Origin: null DNT: 1 Connection: keep-alive Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8K<...>NaM5Tw== Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-site Pragma: no-cache Cache-Control: no-cache
更新信息
将Origin值设置为OIDC授权URL(该URL已在Azure App Service认证设置中列为允许的返回URL),请求即可正常工作。目前需排查Identity Server发起的POST请求为何未包含Origin头。
内容的提问来源于stack exchange,提问作者JonHendrix
相关产品推荐
相关产品推荐

