You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Asp.Net Core 3.1 Identity“记住我”设为False在Chrome中失效问题

问题解决:.NET Core 3.1 Identity Core 中Chrome浏览器“记住我”设为False仍保持登录

可能原因分析

Chrome浏览器默认启用了后台持续运行和会话恢复功能,即使关闭浏览器窗口,后台进程仍会保留会话Cookie,导致重新打开浏览器时仍处于登录状态。此外,也可能是Identity Cookie的配置未明确区分会话Cookie与持久Cookie的行为。

解决方案

1. 显式配置Identity Cookie的会话行为

在Startup.cs的ConfigureServices方法中,修改Application Cookie的配置,确保当“记住我”未勾选时,Cookie为严格的会话级Cookie:

services.ConfigureApplicationCookie(options =>
{
    options.Cookie.HttpOnly = true;
    options.Cookie.SameSite = SameSiteMode.Lax;
    options.Cookie.SecurePolicy = CookieSecurePolicy.Always; // 生产环境建议启用HTTPS
    options.SlidingExpiration = true;
    
    // 明确会话Cookie的处理:当IsPersistent为false时,Cookie随浏览器关闭失效
    options.Events.OnSigningIn = context =>
    {
        if (!context.Properties.IsPersistent)
        {
            context.CookieOptions.Expires = null; // 设为会话Cookie
        }
        return Task.CompletedTask;
    };
});

2. 手动控制登录时的AuthenticationProperties

替代原有的PasswordSignInAsync,手动验证用户并设置登录属性,确保IsPersistent参数正确作用:

[HttpPost]
[AllowAnonymous]
public async Task<IActionResult> Login(Login model, string returnUrl="/")
{
    if (ModelState.IsValid)
    {
        var user = await _userManager.FindByEmailAsync(model.Email);
        if (user != null && await _userManager.CheckPasswordAsync(user, model.Password))
        {
            // 获取用户Claims
            var claimsPrincipal = await _signInManager.CreateUserPrincipalAsync(user);
            
            // 配置登录属性
            var authProps = new AuthenticationProperties
            {
                IsPersistent = model.RememberMe,
                // 仅当"记住我"勾选时设置持久化过期时间
                ExpiresUtc = model.RememberMe ? DateTimeOffset.UtcNow.AddDays(7) : null
            };
            
            // 执行登录
            await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme, claimsPrincipal, authProps);
            
            // 后续跳转逻辑保持不变
            if (!String.IsNullOrEmpty(returnUrl) && Url.IsLocalUrl(returnUrl) && returnUrl != "/")
            {
                return LocalRedirect(returnUrl);
            }
            else
            {
                TempData["UserLanguage"] = user.UserLanguage;
                var LoggedInUserId = _userManager.GetUserId(claimsPrincipal);
                var MenuVM = await _dataAccessService.GetDefaultPage(LoggedInUserId);
                if (MenuVM != null)
                {
                    return RedirectToAction(MenuVM.ActionName, MenuVM.ControllerName);
                }
                else
                {
                    return LocalRedirect(returnUrl);
                }
            }
        }
        ModelState.AddModelError(string.Empty, "Invalid Login Attempt");
    }
    return View(model);
}

3. 验证Chrome浏览器设置(用户端可选)

让用户检查Chrome的以下设置,避免会话恢复干扰:

  • 关闭「继续运行后台应用,即使Chrome已关闭」:设置 > 系统 > 继续运行后台应用
  • 关闭「重新打开时恢复网页」:设置 > 启动时 > 选择「打开新标签页」

验证步骤

  1. 设置「记住我」为False并登录
  2. 完全关闭Chrome(包括后台进程,可通过任务管理器结束所有Chrome进程)
  3. 重新打开Chrome并访问应用,确认已退出登录

内容的提问来源于stack exchange,提问作者Zain ul abedin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 03:57:02