You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core 5 Windows身份认证下React客户端CORS错误求助

问题描述

我创建了一个.NET Core 5项目,选择Windows身份认证。React客户端调用接口时出现CORS错误,选择“无”身份认证则无此问题。

客户端调用代码:

const res = await fetch(`https://localhost:44373/weatherforecast`)

因业务需要必须使用AD认证,已尝试在fetch中添加配置:

const res = await fetch(`https://localhost:44373/weatherforecast`, { credentials: 'include' })

并修改了Startup文件(当前代码如下),但问题仍未解决:

using Microsoft.AspNetCore.Builder;
using Microsoft.AspNetCore.Hosting;
using Microsoft.AspNetCore.HttpsPolicy;
using Microsoft.AspNetCore.Mvc;
using Microsoft.Extensions.Configuration;
using Microsoft.Extensions.DependencyInjection;
using Microsoft.Extensions.Hosting;
using Microsoft.Extensions.Logging;
using System;
using System.Collections.Generic;
using System.Linq;
using System.Threading.Tasks;

namespace WebApplication3
{
    public class Startup
    {
        public Startup(IConfiguration configuration)
        {
            Configuration = configuration;
        }

        public IConfiguration Configuration { get; }

        public void ConfigureServices(IServiceCollection services)
        {
            services.AddControllers();
            services.AddCors(options =>
            {
                options.AddPolicy("MyAllowCredentialsPolicy",
                    policy =>
                    {
                        policy.WithOrigins("https://localhost:44300")
                               .AllowCredentials();
                    });
            });
        }

        public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
        {
            if (env.IsDevelopment())
            {
                app.UseDeveloperExceptionPage();
            }

            app.UseHttpsRedirection();

            app.UseCors();

            app.UseRouting();

            app.UseAuthorization();

            app.UseEndpoints(endpoints =>
            {
                endpoints.MapControllers();
            });
        }
    }
}

解决方案

针对Windows身份认证场景下的CORS问题,需调整以下几点:

1. 修正CORS策略应用与中间件顺序

  • 当前app.UseCors()未指定自定义策略名,需改为指定你创建的MyAllowCredentialsPolicy
  • 必须添加UseAuthentication()中间件(Windows身份认证依赖此中间件,你的代码中缺失)
  • 调整中间件顺序,确保UseCors在UseRouting之后、UseAuthentication之前

修改后的Configure方法:

public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
{
    if (env.IsDevelopment())
    {
        app.UseDeveloperExceptionPage();
    }

    app.UseHttpsRedirection();

    app.UseRouting();

    // 指定CORS策略
    app.UseCors("MyAllowCredentialsPolicy");

    // 添加Windows身份认证中间件
    app.UseAuthentication();

    app.UseAuthorization();

    app.UseEndpoints(endpoints =>
    {
        endpoints.MapControllers();
    });
}

2. 完善CORS策略配置

Windows身份认证的预检请求(OPTIONS)需要允许所有请求头和方法,同时确保来源正确:

修改ConfigureServices中的CORS配置:

services.AddCors(options =>
{
    options.AddPolicy("MyAllowCredentialsPolicy",
        policy =>
        {
            policy.WithOrigins("https://localhost:44300") // 替换为你的React客户端地址
                  .AllowAnyHeader()
                  .AllowAnyMethod()
                  .AllowCredentials();
        });
});

3. 配置Windows身份认证服务

在ConfigureServices中添加Windows身份认证的服务注册:

services.AddAuthentication(NegotiateDefaults.AuthenticationScheme)
        .AddNegotiate();

4. 允许OPTIONS请求匿名访问(关键)

Windows身份认证默认会拦截OPTIONS预检请求,需要在项目根目录的web.config中添加配置,允许OPTIONS请求匿名访问:

<?xml version="1.0" encoding="utf-8"?>
<configuration>
  <system.webServer>
    <security>
      <authentication>
        <anonymousAuthentication enabled="false" />
        <windowsAuthentication enabled="true" />
      </authentication>
      <authorization>
        <!-- 允许OPTIONS请求匿名访问 -->
        <add accessType="Allow" users="*" verbs="OPTIONS" />
      </authorization>
    </security>
  </system.webServer>
</configuration>

5. 确认客户端请求地址正确

确保fetch请求的URL是后端服务的正确地址,比如后端运行在https://localhost:44373,则客户端代码应为:

const res = await fetch(`https://localhost:44373/weatherforecast`, { credentials: 'include' })

内容的提问来源于stack exchange,提问作者programmer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 22:20:29