You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure App Service认证与Duende Identity Server的403权限问题

问题背景与现象

我们有一个受Duende Identity Server 6保护的.NET 6 Web应用,部署在Azure App Service上运行正常。现在要在Azure App Service前添加Azure App Service认证,强制用户访问前必须通过公司Active Directory(含MFA)验证。

当前Web应用是OIDC客户端,会调用自有凭证存储的Duende OIDC Identity Server。Azure App Service认证对接企业AD已配置生效,用户必须先完成认证才能访问Web应用,但在Duende Identity Server登录后,页面重定向至https://webapp.com/signin-oidc时返回403禁止访问。经测试,拦截该请求并移除User-Agent头后可正常访问,推测和CORS相关。

已尝试的配置
  • 在webapp.com上设置Allowed Origins为"*"
  • 在Identity Server应用上设置Allowed Origins为"*"
  • 在Azure App Service认证设置中添加允许的重定向URL:https://webapp.com/signin-oidc
疑问

是否还有遗漏的配置或需要考虑的方向?

复现代码(基础ASP.NET 6 MVC)
using System.IdentityModel.Tokens.Jwt;

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.
builder.Services.AddControllersWithViews();

JwtSecurityTokenHandler.DefaultMapInboundClaims = false;

builder.Services.AddAuthentication(options =>
{
    options.DefaultScheme = "Cookies";
    options.DefaultChallengeScheme = "oidc";
})
    .AddCookie("Cookies")
    .AddOpenIdConnect("oidc", options =>
    {
        options.Authority = "https://our-login-authority-url.com";

        options.ClientId = "com.company.app";
        options.ClientSecret = "<.. secret ..>";
        options.ResponseType = "code";
        options.UsePkce = true;

        options.Scope.Clear();
        options.Scope.Add("openid");
        options.Scope.Add("profile");
        options.Scope.Add("offline_access");

        // keeps id_token smaller
        options.GetClaimsFromUserInfoEndpoint = true;
        options.SaveTokens = true;
    });

var app = builder.Build();

// Configure the HTTP request pipeline.
if (!app.Environment.IsDevelopment())
{
    app.UseExceptionHandler("/Home/Error");
    // The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
    app.UseHsts();
}

app.UseHttpsRedirection();
app.UseStaticFiles();

app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

app.MapControllerRoute(
    name: "default",
    pattern: "{controller=Home}/{action=Index}/{id?}")
    .RequireAuthorization();

app.Run();
网络请求信息

POST /signin-oidc请求头

POST /signin-oidc HTTP/1.1
Host: mywebapp.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: nl,en-US;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate, br
Content-Type: application/x-www-form-urlencoded
Content-Length: 699
Origin: null
DNT: 1
Connection: keep-alive
Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8K<...>NaM5Tw==
Upgrade-Insecure-Requests: 1
Sec-Fetch-Dest: document
Sec-Fetch-Mode: navigate
Sec-Fetch-Site: same-site
Pragma: no-cache
Cache-Control: no-cache

更新信息

将Origin值设置为OIDC授权URL(该URL已在Azure App Service认证设置中列为允许的返回URL),请求即可正常工作。目前需排查Identity Server发起的POST请求为何未包含Origin头。


内容的提问来源于stack exchange,提问作者JonHendrix

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 08:54:59