Kentico 13 .NET Core门户自定义OpenId外部认证失败排查
排查Kentico 13 .NET Core集成自定义Identity Server时
GetExternalLoginInfoAsync返回null的问题 首先确认:你采用的外部OIDC认证集成到Kentico 13 .NET Core门户的模式是正确的,问题出在配置细节或流程上,以下是针对性排查点:
1. 认证中间件顺序错误
Kentico的Xperience身份服务中间件必须优先于外部认证(OpenIdConnect)注册,且UseAuthentication要在Kentico核心中间件前执行:
// Startup.cs 配置服务部分 services.AddKentico(features => { features.SetAdminCookiesSameSitePolicy(SameSiteMode.None); features.UsePageBuilder(); }) .AddAuthentication() // 优先注册Kentico默认Cookie或自定义Cookie .AddCookie(Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme) // 再注册Identity Server的OIDC认证 .AddOpenIdConnect("IdentityServer", options => { options.Authority = "https://your-identity-server-url"; options.ClientId = "your-client-id"; options.ClientSecret = "your-client-secret"; options.ResponseType = "code id_token"; options.Scope.Add("openid"); options.Scope.Add("profile"); options.SaveTokens = true; options.GetClaimsFromUserInfoEndpoint = true; }); // Startup.cs 配置请求管道部分 app.UseHttpsRedirection(); app.UseAuthentication(); // 必须在UseAuthorization和UseKentico之前 app.UseAuthorization(); app.UseKentico();
2. 回调路径与Identity Server配置不匹配
确保OIDC的CallbackPath和Identity Server客户端配置的重定向URI完全一致(包含协议、域名、路径):
// OIDC配置中指定回调路径 options.CallbackPath = "/signin-oidc";
同时在Identity Server的客户端配置里添加:https://your-kentico-site-domain/signin-oidc作为有效重定向URI。
3. 缺失Kentico外部登录映射配置
需要显式告诉Kentico如何关联外部认证提供商,在服务配置中添加:
services.Configure<AuthenticationOptions>(options => { options.DefaultChallengeScheme = "IdentityServer"; options.DefaultScheme = Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme; }); // 配置Kentico外部登录映射 services.Configure<ExternalAuthenticationOptions>(options => { options.ExternalProviders.Add(new ExternalAuthenticationProviderConfiguration { AuthenticationScheme = "IdentityServer", // 必须与AddOpenIdConnect的名称一致 Name = "Custom Identity Server", ClaimMapping = new Dictionary<string, string> { { ClaimTypes.Email, ClaimTypes.Email }, { ClaimTypes.NameIdentifier, "sub" } // 映射Identity Server的sub字段为Kentico用户唯一标识 } }); });
4. GetExternalLoginInfoAsync调用时机错误
该方法只能在外部认证回调Action中调用,确保回调路由与OIDC的CallbackPath对应:
[HttpGet("/signin-oidc")] public async Task<IActionResult> ExternalLoginCallback(string returnUrl = null) { // 必须在回调流程中调用,此时外部认证Cookie已生成 var loginInfo = await _signInManager.GetExternalLoginInfoAsync(); if (loginInfo == null) { // 处理获取失败逻辑 return RedirectToAction("Login"); } // 后续执行外部登录逻辑 var result = await _signInManager.ExternalLoginSignInAsync(loginInfo.LoginProvider, loginInfo.ProviderKey, isPersistent: false); if (result.Succeeded) { return LocalRedirect(returnUrl); } // 处理用户未注册等场景 return View("ExternalLoginConfirmation", new { Email = loginInfo.Principal.FindFirstValue(ClaimTypes.Email) }); }
5. Cookie SameSite/Secure设置不兼容
若站点使用HTTPS,需确保Cookie配置符合跨域要求:
// 在AddCookie或Kentico Cookie配置中设置 services.Configure<CookieAuthenticationOptions>(Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme, options => { options.Cookie.SameSite = SameSiteMode.None; options.Cookie.SecurePolicy = CookieSecurePolicy.Always; });
同时Identity Server端的Cookie也要做相同配置。
6. Identity Server返回Claims缺失关键字段
GetExternalLoginInfoAsync依赖外部身份提供方返回唯一标识Claim(通常是sub),需在OIDC配置中显式映射:
options.ClaimActions.MapUniqueJsonKey(ClaimTypes.NameIdentifier, "sub");
确保Identity Server的id_token或UserInfo接口返回sub字段。
内容的提问来源于stack exchange,提问作者Deviprasad Das
相关产品推荐
相关产品推荐

