You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft.AspNetCore.Identity重置密码仅服务器端报无效令牌问题

密码重置功能部署后令牌无效问题排查求助

我是一名初级开发者,正在为WebApp开发密码重置功能。本地环境运行一切正常,但部署到服务器后却出现无效令牌错误,无法确定原因。

相关代码

public async Task<IActionResult> ForgotPassword(ForgotPasswordViewModel model)
{
            if (ModelState.IsValid)
            {
                var user = await _userManager.FindByEmailAsync(model.Email);
                if (user == null)
                {
                    // Don't reveal that the user does not exist or is not confirmed
                    return RedirectToAction(nameof(ForgotPasswordConfirmation));
                }

                var code = await _userManager.GeneratePasswordResetTokenAsync(user);
                var callbackUrl = Url.ResetPasswordCallbackLink(user.Id, code, Request.Scheme);
                // Go to the change password page
                Response.Redirect(callbackUrl);
            }

            // If we got this far, something failed, redisplay form
            return View(model);
}

已做排查

  • 确认服务器上的AccountController.cs文件与本地代码完全一致
  • 令牌包含+等特殊字符,本地生成的URL格式类似http://localhost:5000/Account/ResetPassword?userId=00c2a3ad-64c8-49d3-95e5-49a120831b85&code=CfDJ8MVJi%2BoeOmp...,但服务器端生成的callbackUrl出现%25编码问题(%25是UTF-8中%的编码),怀疑存在重复编码情况
  • 尝试用code = HttpUtility.UrlEncode(code)手动编码令牌,结果令牌反而更容易失效,该思路可能有误
  • 已检查并统一本地与服务器的.NET版本,问题仍未解决

目前怀疑令牌被重复编码(例如+先被编码为%2F,之后又被二次编码为%252F),但未手动执行过编码操作,推测可能是服务器配置导致,希望得到解决线索或方案。

内容的提问来源于stack exchange,提问作者Lap1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 09:01:15