.NET Core 5 Windows身份认证下React客户端CORS错误求助
问题描述
我创建了一个.NET Core 5项目,选择Windows身份认证。React客户端调用接口时出现CORS错误,选择“无”身份认证则无此问题。
客户端调用代码:
const res = await fetch(`https://localhost:44373/weatherforecast`)
因业务需要必须使用AD认证,已尝试在fetch中添加配置:
const res = await fetch(`https://localhost:44373/weatherforecast`, { credentials: 'include' })
并修改了Startup文件(当前代码如下),但问题仍未解决:
using Microsoft.AspNetCore.Builder; using Microsoft.AspNetCore.Hosting; using Microsoft.AspNetCore.HttpsPolicy; using Microsoft.AspNetCore.Mvc; using Microsoft.Extensions.Configuration; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Hosting; using Microsoft.Extensions.Logging; using System; using System.Collections.Generic; using System.Linq; using System.Threading.Tasks; namespace WebApplication3 { public class Startup { public Startup(IConfiguration configuration) { Configuration = configuration; } public IConfiguration Configuration { get; } public void ConfigureServices(IServiceCollection services) { services.AddControllers(); services.AddCors(options => { options.AddPolicy("MyAllowCredentialsPolicy", policy => { policy.WithOrigins("https://localhost:44300") .AllowCredentials(); }); }); } public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } app.UseHttpsRedirection(); app.UseCors(); app.UseRouting(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapControllers(); }); } } }
解决方案
针对Windows身份认证场景下的CORS问题,需调整以下几点:
1. 修正CORS策略应用与中间件顺序
- 当前
app.UseCors()未指定自定义策略名,需改为指定你创建的MyAllowCredentialsPolicy - 必须添加
UseAuthentication()中间件(Windows身份认证依赖此中间件,你的代码中缺失) - 调整中间件顺序,确保
UseCors在UseRouting之后、UseAuthentication之前
修改后的Configure方法:
public void Configure(IApplicationBuilder app, IWebHostEnvironment env) { if (env.IsDevelopment()) { app.UseDeveloperExceptionPage(); } app.UseHttpsRedirection(); app.UseRouting(); // 指定CORS策略 app.UseCors("MyAllowCredentialsPolicy"); // 添加Windows身份认证中间件 app.UseAuthentication(); app.UseAuthorization(); app.UseEndpoints(endpoints => { endpoints.MapControllers(); }); }
2. 完善CORS策略配置
Windows身份认证的预检请求(OPTIONS)需要允许所有请求头和方法,同时确保来源正确:
修改ConfigureServices中的CORS配置:
services.AddCors(options => { options.AddPolicy("MyAllowCredentialsPolicy", policy => { policy.WithOrigins("https://localhost:44300") // 替换为你的React客户端地址 .AllowAnyHeader() .AllowAnyMethod() .AllowCredentials(); }); });
3. 配置Windows身份认证服务
在ConfigureServices中添加Windows身份认证的服务注册:
services.AddAuthentication(NegotiateDefaults.AuthenticationScheme) .AddNegotiate();
4. 允许OPTIONS请求匿名访问(关键)
Windows身份认证默认会拦截OPTIONS预检请求,需要在项目根目录的web.config中添加配置,允许OPTIONS请求匿名访问:
<?xml version="1.0" encoding="utf-8"?> <configuration> <system.webServer> <security> <authentication> <anonymousAuthentication enabled="false" /> <windowsAuthentication enabled="true" /> </authentication> <authorization> <!-- 允许OPTIONS请求匿名访问 --> <add accessType="Allow" users="*" verbs="OPTIONS" /> </authorization> </security> </system.webServer> </configuration>
5. 确认客户端请求地址正确
确保fetch请求的URL是后端服务的正确地址,比如后端运行在https://localhost:44373,则客户端代码应为:
const res = await fetch(`https://localhost:44373/weatherforecast`, { credentials: 'include' })
内容的提问来源于stack exchange,提问作者programmer
相关产品推荐
相关产品推荐

