You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Web Apps + AAD B2C登出异常:点击登出后仍保持登录

Razor WebAssembly + Azure AD B2C 登出功能异常排查

我开发了一个简单的Razor WebAssembly应用,采用Azure Active Directory B2C作为用户认证与授权的可信源。登录流程正常:访问StaticWebApp的URL时,会按预期跳转到登录页面,输入用户名和密码登录成功后,应用主页会显示当前登录用户的邮箱。但点击登出按钮后,虽按预期跳转到登录页面,实际并未完成登出操作——再次访问应用时,无需重新登录就会直接显示已登录状态。

我的staticwebapp.config.json配置

{
    "responseOverrides": {
        "401": {
            "statusCode": 302,
            "redirect": "/.auth/login/aadb2c"
        }
    },
    "routes": [
        {
            "route": "/.auth/login/aadb2c",
            "allowedRoles": [ "anonymous" ]
        },
        {
            "route": "/.auth/login/aad",
            "allowedRoles": [ "anonymous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/.auth/login/apple",
            "allowedRoles": [ "anonymous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/.auth/login/facebook",
            "allowedRoles": [ "anonymous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/.auth/login/github",
            "allowedRoles": [ "anonymous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/.auth/login/google",
            "allowedRoles": [ "anonyous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/.auth/login/twitter",
            "allowedRoles": [ "anonymous", "authenticated" ],
            "statusCode": 404
        },
        {
            "route": "/login*",
            "allowedRoles": [ "anonymous" ],
            "rewrite": "/.auth/login/aadb2c"
        },
        {
            "route": "/logout*",
            "allowedRoles": [ "authenticated" ],
            "rewrite": "/.auth/logout"
        },
        {
            "route": "/.auth/me",
            "allowedRoles": ["authenticated","anonymous"]
        }
    ],
    "auth": {
        "identityProviders": {
            "customOpenIdConnectProviders": {
                "aadb2c": {
                    "registration": {
                        "clientIdSettingName": "AADB2C_PROVIDER_CLIENT_ID",
                        "clientCredential": {
                            "clientSecretSettingName": "AADB2C_PROVIDER_CLIENT_SECRET"
                        },
                        "openIdConnectConfiguration": {
                            "wellKnownOpenIdConfiguration": "https://{tenantId}.b2clogin.com/{tenantId}.onmicrosoft.com/v2.0/.well-known/openid-configuration?p={userFlowName}"
                        }
                    },
                    "login": {
                        "nameClaimType": "emails",
                        "scopes": ["openid"]
                    }
                }
            }
        }
    }
}

主页使用的LoginDisplay Razor组件代码

<AuthorizeView>
    <Authorized>
        Hello @context.User?.Identity?.Name!
        <a href="/logout">Log out</a>
    </Authorized>
    <NotAuthorized>
        <a href="/login">Log in</a>
    </NotAuthorized>
</AuthorizeView>

补充信息

  • 用户流中「Require ID Token in logout requests」属性已设置为True
  • 已注册应用的「Front-channel logout URL」设置为https://{NAME}.azurestaticapps.net/.auth/logout

请问我遗漏了什么配置或步骤?


内容的提问来源于stack exchange,提问作者user2896152

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 02:45:42