Azure B2C修改重定向URI后返回旧地址,生效延迟问题求助
Azure B2C重定向URI修改后延迟生效问题的背景咨询
在Blazor应用中使用Azure B2C时遇到以下问题:
- 此前使用
https://localhost:7078/signin-oidc_B2C作为重定向URI测试,一切正常 - 修改为
https://localhost:4436/signin-oidc_B2C后,登录时收到**"新URI未在租户中注册"**的错误,且实际被重定向到旧URI - 排查代码和Azure B2C配置后,问题仍时好时坏,最终确认是生效延迟问题,等待20-30分钟后授权流程自动恢复正常
具体信息
Azure B2C配置截图

Program.cs中的AddAuthentication代码
builder.Services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = $"UNKNOWN"; }) .AddCookie() .AddOpenIdConnect($"{OpenIdConnectDefaults.AuthenticationScheme}_B2C", options => { var instance = config["AzureAdB2C:Instance"]; var tenantId = config["AzureAdB2C:TenantId"]; var domain = config["AzureAdB2C:Domain"]; var signUpSignInPolicyId = config["AzureAdB2C:SignUpSignInPolicyId"]; //B2C authority options.Authority = $"https://{domain}.b2clogin.com/{domain}.onmicrosoft.com/{signUpSignInPolicyId}/"; options.MetadataAddress = $"https://{domain}.b2clogin.com/{domain}.onmicrosoft.com/{signUpSignInPolicyId}/v2.0/.well-known/openid-configuration"; options.ClientId = config["Secret_AzureAdB2C:ClientId"] ; options.ClientSecret = config["Secret_AzureAdB2C:ClientSecret"]; options.ResponseType = OpenIdConnectResponseType.Code; options.ResponseMode = OpenIdConnectResponseMode.Query; options.SignInScheme = $"{CookieAuthenticationDefaults.AuthenticationScheme}"; options.CallbackPath = config["AzureAdB2C:CallbackPath"]; options.SignedOutCallbackPath = config["AzureAdB2C:SignedOutCallbackPath"] ; var scopes = config["AzureAdB2C:Scopes"]; if (!string.IsNullOrEmpty(scopes)) { foreach (var scope in scopes.Split(" ")) { options.Scope.Add(scope); } } })
发送的授权请求
https://sabrepmb2c.b2clogin.com/sabrepmb2c.onmicrosoft.com/b2c_1_signupsignin/oauth2/v2.0/authorize? client_id=a955156f-XXXX349452527a &redirect_uri=https%3A%2F%2Flocalhost%3A4436%2Fsignin-oidc_B2C &response_type=code &scope=openid%20profile%20offline_access%20https%3A%2F%2FsabrepmB2C.onmicrosoft.com%2Fa955156f-b210-40a2-9398-95349452527a%2Faccess-as-user &code_challenge=x27PtwIXXXXXXXXXdsZwdSRaoSa-w&x-client-SKU=ID_NET6_0&x-client-ver=6.30.0.0;
返回的响应
https://localhost:7078/signin-oidc_B2C?error=redirect_uri_mismatch&error_description=AADB2C90006%3a+ The+redirect+URI+%27https%3a%2f%2flocalhost%3a4436%2fsignin-oidc_B2C%27+provided+in+the+request+is+not+registered+for+ client+id+%27a955156f-XXXXXXX-949452527a%27.%0d%0a Correlation+ID%3a+bd47cefc-5c30-4171-9e41-155fbd4bb9d3%0d%0aTimestamp%3a+2023-06-03+04%3a30%3a32Z%0d%0a&state=CfDJ8GgXXXXXXXXXSRaoSa-w
注意:响应中的重定向地址为旧URI,与授权请求中的新URI不符,属于异常行为。
现寻求关于该问题的更多背景信息。
内容的提问来源于stack exchange,提问作者gwruck
相关产品推荐
相关产品推荐

