Microsoft.AspNetCore.Identity重置密码仅服务器端报无效令牌问题
密码重置功能部署后令牌无效问题排查求助
我是一名初级开发者,正在为WebApp开发密码重置功能。本地环境运行一切正常,但部署到服务器后却出现无效令牌错误,无法确定原因。
相关代码
public async Task<IActionResult> ForgotPassword(ForgotPasswordViewModel model) { if (ModelState.IsValid) { var user = await _userManager.FindByEmailAsync(model.Email); if (user == null) { // Don't reveal that the user does not exist or is not confirmed return RedirectToAction(nameof(ForgotPasswordConfirmation)); } var code = await _userManager.GeneratePasswordResetTokenAsync(user); var callbackUrl = Url.ResetPasswordCallbackLink(user.Id, code, Request.Scheme); // Go to the change password page Response.Redirect(callbackUrl); } // If we got this far, something failed, redisplay form return View(model); }
已做排查
- 确认服务器上的AccountController.cs文件与本地代码完全一致
- 令牌包含+等特殊字符,本地生成的URL格式类似
http://localhost:5000/Account/ResetPassword?userId=00c2a3ad-64c8-49d3-95e5-49a120831b85&code=CfDJ8MVJi%2BoeOmp...,但服务器端生成的callbackUrl出现%25编码问题(%25是UTF-8中%的编码),怀疑存在重复编码情况 - 尝试用
code = HttpUtility.UrlEncode(code)手动编码令牌,结果令牌反而更容易失效,该思路可能有误 - 已检查并统一本地与服务器的.NET版本,问题仍未解决
目前怀疑令牌被重复编码(例如+先被编码为%2F,之后又被二次编码为%252F),但未手动执行过编码操作,推测可能是服务器配置导致,希望得到解决线索或方案。
内容的提问来源于stack exchange,提问作者Lap1
相关产品推荐
相关产品推荐

