You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core 6结合独立账户与Microsoft.Identity.Web认证遇加载错误

解决ASP.NET Core 6 + Microsoft.Identity.Web + Identity 外部登录错误:Error loading external login information

核心问题原因

错误源于ASP.NET Core Identity与Microsoft.Identity.Web的认证配置冲突:

  • AddDefaultIdentity会默认将Cookie认证设为默认方案,用于管理本地用户会话;
  • AddMicrosoftIdentityWebAppAuthentication会强制将OpenID Connect(OIDC)设为默认认证方案,覆盖了Identity的Cookie配置,导致外部登录回调时无法正确映射到Identity的用户流程。

同时,当前配置未正确将Azure AD注册为Identity的外部登录提供者,缺少必要的用户信息映射和回调处理逻辑。

修复步骤

1. 修改Program.cs的服务配置

替换现有认证相关代码,确保Identity的Cookie认证为默认,同时将Azure AD作为外部登录提供者添加:

using AuthTest.Data;
using Microsoft.AspNetCore.Identity;
using Microsoft.EntityFrameworkCore;
using Microsoft.AspNetCore.Authentication.OpenIdConnect;
using Microsoft.Identity.Web;

var builder = WebApplication.CreateBuilder(args);

var connectionString = builder.Configuration.GetConnectionString("DefaultConnection");

builder.Services.AddDbContext<ApplicationDbContext>(options =>
    options.UseSqlServer(connectionString));
builder.Services.AddDatabaseDeveloperPageExceptionFilter();

// 配置Identity并启用默认UI(包含外部登录页面)
builder.Services.AddDefaultIdentity<IdentityUser>(options => options.SignIn.RequireConfirmedAccount = true)
    .AddEntityFrameworkStores<ApplicationDbContext>()
    .AddDefaultUI(); // 新增:启用Identity默认UI,包含外部登录入口

// 配置认证:保留Cookie为默认方案,添加Azure AD作为外部OIDC提供者
builder.Services.AddAuthentication()
    .AddMicrosoftIdentityWebApp(builder.Configuration, OpenIdConnectDefaults.AuthenticationScheme);

// 自定义OIDC参数(可选,设置名称声明)
builder.Services.Configure<OpenIdConnectOptions>(OpenIdConnectDefaults.AuthenticationScheme, options =>
{
    options.TokenValidationParameters.NameClaimType = "name";
});

builder.Services.AddControllersWithViews();

var app = builder.Build();

if (app.Environment.IsDevelopment())
{
    app.UseMigrationsEndPoint();
}
else
{
    app.UseExceptionHandler("/Home/Error");
    app.UseHsts();
}

app.UseHttpsRedirection();
app.UseStaticFiles();

app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

app.MapControllerRoute(
    name: "default",
    pattern: "{controller=Home}/{action=Index}/{id?}");
app.MapRazorPages(); // 必须保留,Identity默认UI依赖Razor Pages

app.Run();

2. 验证appsettings.json配置

确保AzureAd节点参数准确:

  • TenantId:你的Azure AD租户ID(GUID或租户域名均可)
  • ClientId:Azure AD应用注册的客户端ID
  • ClientSecret:应用注册生成的客户端密钥(确认未过期)
  • CallbackPath:必须与Azure AD应用注册中配置的重定向URI完全一致(本地开发格式为https://localhost:<项目端口>/signin-oidc)

3. 数据库迁移与初始化

打开Package Manager Console,执行以下命令完成Identity数据库初始化:

Add-Migration InitialCreate
Update-Database

4. Azure AD应用注册配置检查

  • 在Azure门户的应用注册中,添加重定向URI:https://localhost:<你的项目端口>/signin-oidc(本地开发时需对应项目实际端口)
  • 确认应用注册已启用授权码流(在「认证」→「高级设置」中检查)
  • 为应用注册添加User.Read委托权限,并完成管理员同意

关键注意事项

  • 不要同时使用AddMicrosoftIdentityWebAppAuthentication和AddDefaultIdentity:前者适用于无需本地用户存储的纯AAD认证场景,后者适用于本地用户+外部登录的混合场景。
  • AddDefaultUI()必须添加:否则Identity不会生成外部登录相关的页面(如登录页的外部登录按钮)。
  • 回调URI必须严格匹配:否则Azure AD会拒绝回调请求,直接导致登录失败。

内容的提问来源于stack exchange,提问作者user7148560

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.23 22:05:29