You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Blazor WebAssembly Hosted(.NET 6.0)AAD认证问题:访问WeatherForecast控制器时令牌受众无效及登录弹窗异常

Hey Juan, let's fix your two issues step by step—first the token validation error blocking your API access, then the Edge login popup freeze.

1. Fixing the "invalid_token" (audience mismatch) error

This error occurs because your API expects a different audience value than what’s included in the JWT token from AAD. Here are the key fixes:

a. Correct the server-side Azure AD configuration

Your current server AzureAd config sets ClientId to the API’s application URI (api://1111...), but it should use the API’s actual client ID and explicitly define the valid audience. Update your appsettings.json like this:

"AzureAd": { 
  "Instance": "https://login.microsoftonline.com/", 
  "Domain": "xxxxxx.emea.microsoftonline.com", 
  "TenantId": "22222222-2222-2222-2222-222222222222", 
  "ClientId": "11111111-1111-1111-1111-111111111111", // Use the API's client ID here
  "Audience": "api://11111111-1111-1111-1111-111111111111", // Add this to specify valid audience
  "CallbackPath": "/signin-oidc" 
}

b. Fix the client-side HttpClient naming mismatch

Your client code registers an HttpClient named ReservasSalasAuth.ServerAPI, but then creates a client with {MyNamespace}.ServerAPI—these names must match for the authorization handler to attach the token correctly. Update your client Program.cs to use a consistent name:

// Use a constant to avoid typos
const string ApiClientName = "ReservasSalasAuth.ServerAPI";

builder.Services.AddHttpClient(ApiClientName, client => client.BaseAddress = new Uri(builder.HostEnvironment.BaseAddress))
 .AddHttpMessageHandler<BaseAddressAuthorizationMessageHandler>();

builder.Services.AddScoped(sp => sp.GetRequiredService<IHttpClientFactory>().CreateClient(ApiClientName));

c. Verify the client's access scope

Your current scope (api://1111.../API.Read) looks correct, but double-check that this scope is exposed in your AAD server application (under "Expose an API" in the Azure portal) and that the client application has been granted permission to it.

2. Fixing the Edge login popup freeze

The most obvious culprit here is a mismatch in your client’s Authority configuration—you’re using a tenant ID (fff3a238-b26a-4351-8a2a-0b19dc72e02e) that doesn’t match your actual tenant ID (22222222-2222-2222-2222-222222222222). Let’s fix that and add additional checks:

a. Correct the client's Authority

Update your client appsettings.json to use the right tenant ID:

"AzureAd": { 
  "Authority": "https://login.microsoftonline.com/22222222-2222-2222-2222-222222222222", 
  "ClientId": "33333333-3333-3333-3333-333333333333", 
  "ValidateAuthority": true 
}

b. Additional troubleshooting steps

  • Check Edge's popup blocker: Ensure your app’s domain is allowed to show popups (Edge settings → Cookies and site permissions → Pop-ups and redirects).
  • Clear browser cache/cookies: Old authentication sessions can cause odd behavior—clear cache and cookies for login.microsoftonline.com and your app’s domain.
  • Use Blazor's built-in login methods: Instead of custom logic, use NavigationManager.NavigateToLogin("authentication/login") to trigger login; this is optimized to avoid popup blocking issues.

After making these changes, restart both client and server apps, then test the flow again.

内容的提问来源于stack exchange,提问作者Juan Crespo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.01 03:22:28