You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core 6在线主机10-20分钟自动登出问题求助

ASP.NET Core部署到Plesk Windows主机后自动登出问题

本地运行正常,但部署到带Plesk的Windows主机(推测为IIS环境)后,无论是否设置IsPersistent(保持登录),用户都会在10~20分钟后自动登出。

当前身份验证相关代码如下:

builder.Services.AddAuthentication("MyAuth").AddCookie("MyAuth", options =>
{
    options.Cookie.Name = "MyAuth";
    options.LoginPath = "/login";
    options.LogoutPath = "/logout";
    options.ExpireTimeSpan = TimeSpan.FromDays(30);
});

List<Claim> claims = new()
{
    new Claim(ClaimTypes.NameIdentifier, user.ID.ToString()),
};

ClaimsIdentity identity = new(claims, "MyAuth");

ClaimsPrincipal principal = new(identity);

AuthenticationProperties properties = new() { IsPersistent = login.RememberMe };

await HttpContext.SignInAsync("MyAuth", principal, properties);

已尝试的操作

  • 在AddAuthentication().AddCookie中添加options.SlidingExpiration = true;
  • 在Program.cs中添加builder.Services.Configure<SecurityStampValidatorOptions>(o => o.ValidationInterval = TimeSpan.FromHours(10));
  • 为AuthenticationProperties设置ExpiresUtc

解决方案及Plesk操作步骤

问题根源在于IIS应用池的默认设置:当应用池因空闲超时关闭进程,或进程意外重启时,内存中的身份验证密钥会失效,导致Cookie验证失败。需在Plesk中修改以下两项应用池设置:

  1. 修改应用池空闲超时

    • 登录Plesk面板,找到目标网站对应的应用池
    • 进入应用池的高级设置
    • 找到“空闲超时(分钟)”选项,将值设为0(默认20分钟,设为0表示永不因空闲关闭进程)
  2. 开启加载用户配置文件

    • 同样在应用池的高级设置中
    • 找到“加载用户配置文件”选项,设置为True
    • 此设置会让ASP.NET Core将数据保护密钥存储到系统文件夹%LOCALAPPDATA%/ASP.NET/DataProtection-Keys中,避免进程重启后密钥丢失

内容的提问来源于stack exchange,提问作者user8245153

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 14:12:15