You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Auth0保护Blazor WASM与API时遭遇CORS及401认证问题

Blazor WASM + Auth0 认证API时遇到的问题

我照着Auth0官方教程实现Blazor WASM和API的Auth0身份认证保护,应用自身的认证功能正常,但给API控制器加[Authorize]属性后出了问题:

第一个问题:CORS策略错误

从源https://localhost:7298访问https://localhost:7226/weatherforecast时,因请求资源没有Access-Control-Allow-Origin头被拦截。

我已经在API的program.cs里添加了CORS策略:

builder.Services.AddCors(options =>
{
  options.AddPolicy("Open", builder => builder.WithOrigins("https://localhost:7298").AllowAnyMethod().AllowAnyHeader());
});

第二个问题:401未授权+JSON令牌异常

按照网上方案把app.UseCors移到认证/授权中间件前面后,又出现新问题:接口返回401状态码,同时触发System.Text.Json.JsonException,提示输入无有效JSON令牌。

我已经通过BaseAddressAuthorizationMessageHandler配置了Bearer令牌,但问题依旧。项目代码已上传至GitHub仓库。


内容的提问来源于stack exchange,提问作者Kman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.12 14:25:42