You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

未将授权回退策略设为默认时,Windows Authentication验证失败原因

Blazor Server中使用Negotiate认证时正确处理未认证状态

问题分析

你遇到的核心问题是:未设置FallbackPolicy时,AuthorizeView始终进入<NoResult>状态(显示未认证提示);设置FallbackPolicy后认证正常,但未认证时页面空白。这是因为Negotiate认证的异步特性,初始组件渲染时认证状态未明确,导致AuthorizeView无法判定为<NotAuthorized>,而FallbackPolicy会强制触发全局授权检查,却会拦截未认证请求导致空白。

解决方案

不需要依赖FallbackPolicy,只需在App.razor中添加<NoResult>模板处理认证状态未确定的情况,同时确保认证流程能正确传递用户身份:

1. 修改App.razor,添加<NoResult>分支

在<AuthorizeView>中补充<NoResult>模板,手动判断用户认证状态并渲染对应视图:

<CascadingAuthenticationState>
    <AuthorizeView Policy="Authenticated">
        <Authorized>
            <Router AppAssembly="@typeof(Program).Assembly">
                <Found Context="routeData">
                    <AuthorizeRouteView RouteData="@routeData" DefaultLayout="@typeof(MainLayout)">
                        <NotAuthorized Context="routeViewContext">
                            <AdminContacts>
                                <em>You cannot access the resource.</em>
                                <br />
                                <br />
                                <em>Contact an administrator to change permissions:</em>
                            </AdminContacts>
                        </NotAuthorized>
                    </AuthorizeRouteView>
                </Found>
                <NotFound>
                    <LayoutView Layout="@typeof(MainLayout)">
                        <div class="container">
                            <div class="row">
                                <div class="col p-3">
                                    <em>Sorry, there's nothing at this address.</em>
                                </div>
                            </div>
                        </div>
                    </LayoutView>
                </NotFound>
            </Router>
        </Authorized>
        <NotAuthorized>
            <LayoutView Layout="@typeof(ExternalLayout)">
                <AdminContacts>
                    <em>This user doesn't exist.</em>
                    <br />
                    <br />
                    <em>Contact an administrator for help:</em>
                </AdminContacts>
            </LayoutView>
        </NotAuthorized>
        <NoResult>
            @{
                var authState = await AuthenticationStateProvider.GetAuthenticationStateAsync();
                if (!authState.User.Identity.IsAuthenticated)
                {
                    // 未认证时直接渲染外部布局
                    <LayoutView Layout="@typeof(ExternalLayout)">
                        <AdminContacts>
                            <em>This user doesn't exist.</em>
                            <br />
                            <br />
                            <em>Contact an administrator for help:</em>
                        </AdminContacts>
                    </LayoutView>
                }
                else
                {
                    // 认证状态加载中显示提示
                    <div class="text-center p-5">
                        <em>Loading authentication state...</em>
                    </div>
                }
            }
        </NoResult>
    </AuthorizeView>
</CascadingAuthenticationState>

2. 调整授权策略(可选)

确保Authenticated策略明确拒绝未认证用户,避免模糊状态:

services.AddAuthorization(options =>
{
    options.AddPolicy("Authenticated", p =>
        p.RequireAuthenticatedUser()
          // 添加一个Windows用户必然存在的声明,确保未认证用户被明确拒绝
          .RequireClaim(System.Security.Claims.ClaimTypes.Name));
});

原理说明

  • Negotiate认证是异步触发的,初始组件渲染时AuthenticationState可能处于未确定状态,此时AuthorizeView会进入<NoResult>而非<NotAuthorized>。
  • 通过在<NoResult>中主动获取AuthenticationState,可以明确判断用户是否已认证,从而渲染对应的视图。
  • 避免设置FallbackPolicy,因为它会强制对所有请求执行授权检查,未认证时会直接返回401,导致Blazor组件无法渲染出现空白。

内容的提问来源于stack exchange,提问作者Macadameane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.22 20:07:01