You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Kentico 13 .NET Core门户自定义OpenId外部认证失败排查

排查Kentico 13 .NET Core集成自定义Identity Server时GetExternalLoginInfoAsync返回null的问题

首先确认:你采用的外部OIDC认证集成到Kentico 13 .NET Core门户的模式是正确的,问题出在配置细节或流程上,以下是针对性排查点:


1. 认证中间件顺序错误

Kentico的Xperience身份服务中间件必须优先于外部认证(OpenIdConnect)注册,且UseAuthentication要在Kentico核心中间件前执行:

// Startup.cs 配置服务部分
services.AddKentico(features =>
{
    features.SetAdminCookiesSameSitePolicy(SameSiteMode.None);
    features.UsePageBuilder();
})
.AddAuthentication()
// 优先注册Kentico默认Cookie或自定义Cookie
.AddCookie(Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme)
// 再注册Identity Server的OIDC认证
.AddOpenIdConnect("IdentityServer", options =>
{
    options.Authority = "https://your-identity-server-url";
    options.ClientId = "your-client-id";
    options.ClientSecret = "your-client-secret";
    options.ResponseType = "code id_token";
    options.Scope.Add("openid");
    options.Scope.Add("profile");
    options.SaveTokens = true;
    options.GetClaimsFromUserInfoEndpoint = true;
});

// Startup.cs 配置请求管道部分
app.UseHttpsRedirection();
app.UseAuthentication(); // 必须在UseAuthorization和UseKentico之前
app.UseAuthorization();
app.UseKentico();

2. 回调路径与Identity Server配置不匹配

确保OIDC的CallbackPath和Identity Server客户端配置的重定向URI完全一致(包含协议、域名、路径):

// OIDC配置中指定回调路径
options.CallbackPath = "/signin-oidc";

同时在Identity Server的客户端配置里添加:https://your-kentico-site-domain/signin-oidc作为有效重定向URI。

3. 缺失Kentico外部登录映射配置

需要显式告诉Kentico如何关联外部认证提供商,在服务配置中添加:

services.Configure<AuthenticationOptions>(options =>
{
    options.DefaultChallengeScheme = "IdentityServer";
    options.DefaultScheme = Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme;
});

// 配置Kentico外部登录映射
services.Configure<ExternalAuthenticationOptions>(options =>
{
    options.ExternalProviders.Add(new ExternalAuthenticationProviderConfiguration
    {
        AuthenticationScheme = "IdentityServer", // 必须与AddOpenIdConnect的名称一致
        Name = "Custom Identity Server",
        ClaimMapping = new Dictionary<string, string>
        {
            { ClaimTypes.Email, ClaimTypes.Email },
            { ClaimTypes.NameIdentifier, "sub" } // 映射Identity Server的sub字段为Kentico用户唯一标识
        }
    });
});

4. GetExternalLoginInfoAsync调用时机错误

该方法只能在外部认证回调Action中调用,确保回调路由与OIDC的CallbackPath对应:

[HttpGet("/signin-oidc")]
public async Task<IActionResult> ExternalLoginCallback(string returnUrl = null)
{
    // 必须在回调流程中调用,此时外部认证Cookie已生成
    var loginInfo = await _signInManager.GetExternalLoginInfoAsync();
    if (loginInfo == null)
    {
        // 处理获取失败逻辑
        return RedirectToAction("Login");
    }

    // 后续执行外部登录逻辑
    var result = await _signInManager.ExternalLoginSignInAsync(loginInfo.LoginProvider, loginInfo.ProviderKey, isPersistent: false);
    if (result.Succeeded)
    {
        return LocalRedirect(returnUrl);
    }
    // 处理用户未注册等场景
    return View("ExternalLoginConfirmation", new { Email = loginInfo.Principal.FindFirstValue(ClaimTypes.Email) });
}

若站点使用HTTPS,需确保Cookie配置符合跨域要求:

// 在AddCookie或Kentico Cookie配置中设置
services.Configure<CookieAuthenticationOptions>(Kentico.Authentication.Cookies.CookieAuthenticationDefaults.AuthenticationScheme, options =>
{
    options.Cookie.SameSite = SameSiteMode.None;
    options.Cookie.SecurePolicy = CookieSecurePolicy.Always;
});

同时Identity Server端的Cookie也要做相同配置。

6. Identity Server返回Claims缺失关键字段

GetExternalLoginInfoAsync依赖外部身份提供方返回唯一标识Claim(通常是sub),需在OIDC配置中显式映射:

options.ClaimActions.MapUniqueJsonKey(ClaimTypes.NameIdentifier, "sub");

确保Identity Server的id_token或UserInfo接口返回sub字段。


内容的提问来源于stack exchange,提问作者Deviprasad Das

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 20:10:26