ASP.NET配置仅为反向代理时,如何禁用认证让所有请求通过?
如何将兼具登录与反向代理的应用配置为纯反向代理(跳过本地认证)
要让应用仅作为反向代理、所有请求直接透传至后端API(由后端OAuth2负责认证),核心是移除本地所有认证拦截逻辑,具体操作如下:
1. 移除Cookie认证中间件
当前代码中的UseCookieAuthentication会拦截未认证请求,返回401或重定向到登录页。直接移除或注释掉这段认证中间件的注册代码即可:
修改后的Startup.cs代码:
public void Configuration(IAppBuilder app) { // 移除本地Cookie认证逻辑,不再拦截请求 // if (ConfigHelper.AuthMode == "IISSession") // { // app.UseCookieAuthentication(new CookieAuthenticationOptions // { // AuthenticationType = AuthenticationType, // LoginPath = new PathString("/auth/login"), // //LogoutPath = new PathString("/auth/logout"), // Provider = new CookieAuthenticationProvider { OnApplyRedirect = ApplyRedirect }, // ReturnUrlParameter = "returnUrl", // }); // } // 确保反向代理相关中间件正常注册(例如你的请求重写/转发逻辑) // app.UseReverseProxy(...); // 根据实际反向代理实现调整 }
2. 移除全局授权过滤器
如果应用中配置了全局[Authorize]过滤器,即使移除认证中间件,仍会返回401未授权。需要检查并移除全局授权配置:
示例:移除FilterConfig中的全局过滤器
public class FilterConfig { public static void RegisterGlobalFilters(GlobalFilterCollection filters) { // 移除全局Authorize过滤器 // filters.Add(new AuthorizeAttribute()); filters.Add(new HandleErrorAttribute()); } }
示例:移除Startup中的MVC全局过滤器
public void Configuration(IAppBuilder app) { app.UseMvc(config => { // 移除全局授权过滤器 // config.Filters.Add(new AuthorizeAttribute()); }); }
关键说明
后端API通过OAuth2处理认证时,前端请求会携带OAuth2令牌(如Bearer Token),反向代理只需透传所有请求头和请求内容即可,无需在本地做任何认证校验。
内容的提问来源于stack exchange,提问作者AnthonyDa
相关产品推荐
相关产品推荐

