Asp.Net Core 3.1 Identity“记住我”设为False在Chrome中失效问题
问题解决:.NET Core 3.1 Identity Core 中Chrome浏览器“记住我”设为False仍保持登录
可能原因分析
Chrome浏览器默认启用了后台持续运行和会话恢复功能,即使关闭浏览器窗口,后台进程仍会保留会话Cookie,导致重新打开浏览器时仍处于登录状态。此外,也可能是Identity Cookie的配置未明确区分会话Cookie与持久Cookie的行为。
解决方案
1. 显式配置Identity Cookie的会话行为
在Startup.cs的ConfigureServices方法中,修改Application Cookie的配置,确保当“记住我”未勾选时,Cookie为严格的会话级Cookie:
services.ConfigureApplicationCookie(options => { options.Cookie.HttpOnly = true; options.Cookie.SameSite = SameSiteMode.Lax; options.Cookie.SecurePolicy = CookieSecurePolicy.Always; // 生产环境建议启用HTTPS options.SlidingExpiration = true; // 明确会话Cookie的处理:当IsPersistent为false时,Cookie随浏览器关闭失效 options.Events.OnSigningIn = context => { if (!context.Properties.IsPersistent) { context.CookieOptions.Expires = null; // 设为会话Cookie } return Task.CompletedTask; }; });
2. 手动控制登录时的AuthenticationProperties
替代原有的PasswordSignInAsync,手动验证用户并设置登录属性,确保IsPersistent参数正确作用:
[HttpPost] [AllowAnonymous] public async Task<IActionResult> Login(Login model, string returnUrl="/") { if (ModelState.IsValid) { var user = await _userManager.FindByEmailAsync(model.Email); if (user != null && await _userManager.CheckPasswordAsync(user, model.Password)) { // 获取用户Claims var claimsPrincipal = await _signInManager.CreateUserPrincipalAsync(user); // 配置登录属性 var authProps = new AuthenticationProperties { IsPersistent = model.RememberMe, // 仅当"记住我"勾选时设置持久化过期时间 ExpiresUtc = model.RememberMe ? DateTimeOffset.UtcNow.AddDays(7) : null }; // 执行登录 await HttpContext.SignInAsync(CookieAuthenticationDefaults.AuthenticationScheme, claimsPrincipal, authProps); // 后续跳转逻辑保持不变 if (!String.IsNullOrEmpty(returnUrl) && Url.IsLocalUrl(returnUrl) && returnUrl != "/") { return LocalRedirect(returnUrl); } else { TempData["UserLanguage"] = user.UserLanguage; var LoggedInUserId = _userManager.GetUserId(claimsPrincipal); var MenuVM = await _dataAccessService.GetDefaultPage(LoggedInUserId); if (MenuVM != null) { return RedirectToAction(MenuVM.ActionName, MenuVM.ControllerName); } else { return LocalRedirect(returnUrl); } } } ModelState.AddModelError(string.Empty, "Invalid Login Attempt"); } return View(model); }
3. 验证Chrome浏览器设置(用户端可选)
让用户检查Chrome的以下设置,避免会话恢复干扰:
- 关闭「继续运行后台应用,即使Chrome已关闭」:设置 > 系统 > 继续运行后台应用
- 关闭「重新打开时恢复网页」:设置 > 启动时 > 选择「打开新标签页」
验证步骤
- 设置「记住我」为False并登录
- 完全关闭Chrome(包括后台进程,可通过任务管理器结束所有Chrome进程)
- 重新打开Chrome并访问应用,确认已退出登录
内容的提问来源于stack exchange,提问作者Zain ul abedin
相关产品推荐
相关产品推荐

