ASP.NET Core应用中Azure B2C注册/登录功能异常问题
背景
基于.NET 6构建ASP.NET Core Web应用,参考Azure AD B2C官方示例仓库实现,配置了Google作为身份提供商的用户流。
当前配置
appsettings.json中的AzureAdB2C配置片段:
"AzureAdB2C": { "Instance": "https://b2ctenant.b2clogin.com", "ClientId": "3ae27e38-90a3-43c7-9bac-8d3bf33227f9", "Domain": "b2ctenant.b2clogin.com", "SignedOutCallbackPath": "/signout/B2C_1_susi", "SignUpSignInPolicyId": "b2c_1_susi", "ResetPasswordPolicyId": "b2c_1_reset", "EditProfilePolicyId": "b2c_1_edit_profile" // 可选资料编辑策略 //"CallbackPath": "/signin/B2C_1_sign_up_in" // 默认值为 /signin-oidc }
本地运行地址:https://localhost:44316
触发的异常
用户点击Sign Up/In选项时抛出以下错误:
IOException: IDX20807: 无法从指定地址获取文档:'[类型为'System.String'的PII已隐藏]'。HttpResponseMessage: '[类型为'System.Net.Http.HttpResponseMessage'的PII已隐藏]',HttpResponseMessage.Content: '[类型为'System.String'的PII已隐藏]'。
Microsoft.IdentityModel.Protocols.HttpDocumentRetriever.GetDocumentAsync(string address, CancellationToken cancel)
Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectConfigurationRetriever.GetAsync(string address, IDocumentRetriever retriever, CancellationToken cancel)Microsoft.IdentityModel.Protocols.ConfigurationManager.GetConfigurationAsync(CancellationToken cancel)
InvalidOperationException: IDX20803: 无法从指定地址获取配置:'[类型为'System.String'的PII已隐藏]'。
Microsoft.IdentityModel.Protocols.ConfigurationManager.GetConfigurationAsync(CancellationToken cancel)
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsyncInternal(AuthenticationProperties properties)
Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleChallengeAsync(AuthenticationProperties properties)
Microsoft.AspNetCore.Authentication.AuthenticationHandler.ChallengeAsync(AuthenticationProperties properties)
Microsoft.AspNetCore.Authentication.AuthenticationService.ChallengeAsync(HttpContext context, string scheme, AuthenticationProperties properties)
Microsoft.AspNetCore.Mvc.ChallengeResult.ExecuteResultAsync(ActionContext context)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Awaited|30_0<TFilter, TFilterAsync>(ResourceInvoker invoker, Task lastTask, State next, Scope scope, object state, bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResultExecutedContextSealed context)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.ResultNext<TFilter, TFilterAsync>(ref State next, ref Scope scope, ref object state, ref bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Awaited|28_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, object state, bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Awaited|25_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, object state, bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Rethrow(ResourceExecutedContextSealed context)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.Next(ref State next, ref Scope scope, ref object state, ref bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, object state, bool isCompleted)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Logged|17_1(ResourceInvoker invoker)
Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.g__Logged|17_1(ResourceInvoker invoker)
Microsoft.AspNetCore.Routing.EndpointMiddleware.g__AwaitRequestTask|6_0(Endpoint endpoint, Task requestTask, ILogger logger)
Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context)
Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddlewareImpl.Invoke(HttpContext context)
解决步骤
显示完整错误信息
在Program.cs中添加代码启用PII日志(仅开发环境使用):using Microsoft.IdentityModel.Logging; // 放在builder.Build()之前 IdentityModelEventSource.ShowPII = true;重新运行后,异常会显示具体的配置文档地址,便于定位根源。
修正Domain配置
当前Domain配置错误,应使用B2C租户的初始域名(如yourtenant.onmicrosoft.com),而非b2ctenant.b2clogin.com。修正后配置:"Domain": "b2ctenant.onmicrosoft.com"验证策略与身份提供商配置
- 确认Azure Portal中已创建
b2c_1_susi用户流,且已启用Google作为身份提供商。 - 检查Google开发者平台中,OAuth客户端ID/密钥配置正确,且回调地址与Azure B2C用户流中的配置一致。
- 确认Azure Portal中已创建
验证配置文档可达性
根据启用PII后显示的地址,直接在浏览器访问OpenID Connect配置文档(格式通常为https://{tenant}.b2clogin.com/{tenant}.onmicrosoft.com/{policy}/v2.0/.well-known/openid-configuration),确认返回正常JSON结构。检查本地HTTPS证书
运行dotnet dev-certs https --trust信任本地开发HTTPS证书,避免证书验证失败导致的请求异常。
内容的提问来源于stack exchange,提问作者Kathiea

