You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

DotNet Core 3.1中_Layout.cshtml无法获取登录Post控制器设置的Claims问题求助

解决ClaimsPrincipal在_Layout.cshtml中为null的问题

你遇到的核心问题是:直接设置HttpContext.User仅对当前请求有效,当登录完成后重定向到其他页面时,新请求不会携带这个身份信息——因为你没有把身份持久化到认证Cookie里。下面是具体的解决方案:

1. 先确保配置好认证中间件(以.NET 6+为例)

在Program.cs中,必须先添加认证服务,再按正确顺序配置中间件:

// 添加Cookie认证服务
builder.Services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddCookie(options =>
    {
        options.LoginPath = "/Account/Login"; // 你的登录页面路径
        options.ExpireTimeSpan = TimeSpan.FromDays(7); // 设置Cookie有效期
    });

// 中间件顺序不能乱:先路由,再认证,最后授权
app.UseRouting();
app.UseAuthentication(); // 必须在UseAuthorization之前
app.UseAuthorization();

2. 修改登录控制器代码,用SignInAsync持久化身份

不要直接赋值HttpContext.User,而是通过SignInAsync把身份写入Cookie,这样后续请求会自动加载身份信息:

[HttpPost]
public async Task<IActionResult> Login(LoginViewModel model)
{
    // 省略你的登录验证逻辑...

    var claims = new List<Claim>();
    claims.Add(new Claim("userName", "Jhon")); // 自定义Claim,也可使用ClaimTypes.Name等标准类型
    var userIdentity = new ClaimsIdentity(claims, CookieAuthenticationDefaults.AuthenticationScheme);
    var userPrincipal = new ClaimsPrincipal(userIdentity);

    // 将身份写入Cookie
    await HttpContext.SignInAsync(
        CookieAuthenticationDefaults.AuthenticationScheme,
        userPrincipal,
        new AuthenticationProperties
        {
            IsPersistent = true, // 可根据前端"记住我"勾选状态动态设置
            ExpiresUtc = DateTime.UtcNow.AddDays(7)
        });

    // 登录成功后必须重定向,让新请求读取Cookie中的身份
    return RedirectToAction("Index", "Home");
}

3. 在_Layout.cshtml中安全访问用户信息

访问身份前先判断是否已认证,避免空引用错误:

@if (User.Identity.IsAuthenticated)
{
    <div class="user-bar">
        欢迎回来,@User.FindFirst("userName")?.Value!
        <!-- 若使用标准ClaimTypes.Name,可直接写@User.Identity.Name -->
    </div>
}
else
{
    <a asp-action="Login" asp-controller="Account">登录</a>
}

额外排查点

  • 中间件顺序错误:如果UseAuthentication在UseAuthorization之后,或在UseRouting之前,会导致身份无法被正确加载。
  • 未添加认证服务:若没调用AddAuthentication和AddCookie,SignInAsync会抛出异常,需确认服务配置完整。
  • 未重定向页面:如果登录后直接返回视图而非重定向,当前请求的User有效,但刷新页面后身份会丢失——因为SignInAsync是在响应中设置Cookie,只有新请求才能读取到。

内容的提问来源于stack exchange,提问作者Talha Talha

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 04:27:37