ASP.NET Core 6在线主机10-20分钟自动登出问题求助
ASP.NET Core部署到Plesk Windows主机后自动登出问题
本地运行正常,但部署到带Plesk的Windows主机(推测为IIS环境)后,无论是否设置IsPersistent(保持登录),用户都会在10~20分钟后自动登出。
当前身份验证相关代码如下:
builder.Services.AddAuthentication("MyAuth").AddCookie("MyAuth", options => { options.Cookie.Name = "MyAuth"; options.LoginPath = "/login"; options.LogoutPath = "/logout"; options.ExpireTimeSpan = TimeSpan.FromDays(30); }); List<Claim> claims = new() { new Claim(ClaimTypes.NameIdentifier, user.ID.ToString()), }; ClaimsIdentity identity = new(claims, "MyAuth"); ClaimsPrincipal principal = new(identity); AuthenticationProperties properties = new() { IsPersistent = login.RememberMe }; await HttpContext.SignInAsync("MyAuth", principal, properties);
已尝试的操作
- 在
AddAuthentication().AddCookie中添加options.SlidingExpiration = true; - 在Program.cs中添加
builder.Services.Configure<SecurityStampValidatorOptions>(o => o.ValidationInterval = TimeSpan.FromHours(10)); - 为
AuthenticationProperties设置ExpiresUtc
解决方案及Plesk操作步骤
问题根源在于IIS应用池的默认设置:当应用池因空闲超时关闭进程,或进程意外重启时,内存中的身份验证密钥会失效,导致Cookie验证失败。需在Plesk中修改以下两项应用池设置:
修改应用池空闲超时
- 登录Plesk面板,找到目标网站对应的应用池
- 进入应用池的高级设置
- 找到“空闲超时(分钟)”选项,将值设为
0(默认20分钟,设为0表示永不因空闲关闭进程)
开启加载用户配置文件
- 同样在应用池的高级设置中
- 找到“加载用户配置文件”选项,设置为
True - 此设置会让ASP.NET Core将数据保护密钥存储到系统文件夹
%LOCALAPPDATA%/ASP.NET/DataProtection-Keys中,避免进程重启后密钥丢失
内容的提问来源于stack exchange,提问作者user8245153
相关产品推荐
相关产品推荐

