You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Entity Framework+B2C授权重定向空白页及Postman URI不匹配问题排查

问题排查:AAD B2C重定向空白与URI不匹配错误

问题现象

  • 调用API https://skillbasedmiddleware.azurewebsites.net/tables/useritem?$filter=(email eq '55@55.de') 时,被重定向到登录窗口后页面空白
  • 使用Postman无令牌请求该URL,返回redirect_uri_mismatch错误,错误详情:
<input type='hidden' name='error' id='error' value='redirect_uri_mismatch'/>
<input type='hidden' name='error_description' id='error_description' value='AADB2C90006: The redirect URI&#39;https://skillbasedmiddleware.azurewebsites.net/signin-oidc&#39; provided in the request is not registered for the client id &#39;XXX;. Correlation ID: 586439a6-0be6-45f1-aab2-b382dcb8f935' />

疑问

  1. 重定向后页面空白是否正常?
  2. 为何出现“URI不匹配”错误?

相关配置与代码

API配置(appsettings.json)

{
  "AzureAdB2C": {
    "Instance": "https://xxx.b2clogin.com",
    "ClientId": "yyyy",
    "Domain": "ccc.onmicrosoft.co",
    "SignedOutCallbackPath": "/signout-oidc",
    "SignUpSignInPolicyId": "B2C_1_Client"
  },
  "ConnectionStrings": {
    "DefaultConnection": "Server=(localdb)\\mssqllocaldb;Database=NewDb;Trusted_Connection=True"
  },
  "Logging": {
    "LogLevel": {
      "Default": "Information",
      "Microsoft.AspNetCore": "Warning"
    }
  },
  "AllowedHosts": "*"
}

API启动代码(Program.cs)

var builder = WebApplication.CreateBuilder(args);
var connectionString = builder.Configuration.GetConnectionString("DefaultConnection1");
    
if (connectionString == null)
{
    throw new ApplicationException("DefaultConnection is not set");
}

builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
                .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureADB2C"));
    
builder.Services.AddAuthorization(options =>
{
    // By default, all incoming requests will be authorized according to 
    // the default policy
    options.FallbackPolicy = options.DefaultPolicy;
});
    
builder.Services.AddDbContext<MigrationDbContext>(options => options.UseSqlServer(connectionString));
builder.Services.AddDatasyncControllers();
    
var app = builder.Build();
    
// Initialize the database
using (var scope = app.Services.CreateScope())
{
    var context = scope.ServiceProvider.GetRequiredService<MigrationDbContext>();
    //await context.InitializeDatabaseAsync().ConfigureAwait(false);
}
    
// Configure and run the web service.
app.UseAuthentication();
app.UseAuthorization();
app.MapControllers();
app.Run();

问题根源分析

1. 重定向后页面空白的原因

这不正常,本质是AAD B2C返回错误后,API没有处理该错误场景。当用户被重定向到登录页触发redirect_uri_mismatch错误时,AAD B2C会把错误信息带回/signin-oidc回调地址,但你的API未配置对应的错误处理逻辑,导致页面无内容输出,呈现空白。

2. URI不匹配错误的核心原因

错误信息明确指出https://skillbasedmiddleware.azurewebsites.net/signin-oidc未在客户端IDXXX对应的AAD B2C应用注册中添加。此外,代码和配置存在两处关键错误:

  • 认证配置混搭:你使用了适用于API的JwtBearerDefaults.AuthenticationScheme,却调用了用于Web应用(MVC/Razor Pages)的AddMicrosoftIdentityWebApp方法。这种混搭导致框架错误触发重定向登录逻辑,而API本应直接返回401未授权,而非重定向。
  • 客户端ID不一致:错误中的客户端ID是XXX,但配置文件中是yyyy,说明要么配置文件的ClientId写错,要么AAD B2C应用注册的配置对应了错误的客户端。
  • 回调地址未注册:/signin-oidc回调地址未添加到AAD B2C应用注册的重定向URI列表中(即使API不应使用重定向,错误触发的重定向仍需该地址被注册)。

修正建议

  • 替换认证配置:将AddMicrosoftIdentityWebApp改为API专用的AddMicrosoftIdentityWebApi,配合JwtBearerDefaults.AuthenticationScheme,让API正确返回401而非重定向。
  • 核对应用注册信息:确保配置文件的ClientId与AAD B2C应用注册的ID一致;若需保留重定向逻辑(不推荐API使用),将https://skillbasedmiddleware.azurewebsites.net/signin-oidc添加到应用注册的重定向URI列表。
  • 添加错误处理:在API中配置app.UseExceptionHandler或自定义中间件,避免出现空白页面。

内容的提问来源于stack exchange,提问作者inno

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 23:03:19