如何控制ASP.NET Core Identity DefaultUI登录后自动重定向至LoginWith2fa?
解决登录后自动重定向到LoginWith2fa的问题
问题背景
自定义UserStore后,用户在/Identity/Account/Login提交登录请求,Default UI会自动重定向到/Identity/Account/LoginWith2fa页面,希望简化用户登录流程,暂时禁用2FA相关的自动跳转逻辑。
日志信息
Microsoft.AspNetCore.Routing.EndpointMiddleware: 信息:正在执行终结点 '/Account/LoginWith2fa' Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker: 信息:路由匹配成功 {page = "/Account/LoginWith2fa", area = "Identity", action = "", controller = ""}。正在执行页面 /Account/LoginWith2fa Microsoft.EntityFrameworkCore.Infrastructure: 信息:Entity Framework Core 6.0.7 已初始化 'ApplicationDbContext',使用提供程序 'Pomelo.EntityFrameworkCore.MySql:6.0.2',选项:CommandTimeout=10 ServerVersion 10.5.9-mariadb Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker: 信息:正在执行处理程序方法 Microsoft.AspNetCore.Identity.UI.V5.Pages.Account.Internal.LoginWith2faModel.OnPostAsync - ModelState 有效 BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByIdAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByIdAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserLockoutStore_GetLockoutEnabledAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserAuthenticatorKeyStore_GetAuthenticatorKeyAsync Microsoft.AspNetCore.Identity.UserManager: 警告:VerifyTwoFactorTokenAsync() 对用户验证失败。 BackendAPI.Services.CustomUserStore: 信息:456780: IUserLockoutStore_IncrementAccessFailedCountAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserNameAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByNameAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserNameAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_SetNormalizedUserNameAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_UpdateAsync BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync Microsoft.AspNetCore.Identity.UI.V5.Pages.Account.Internal.LoginWith2faModel: 警告:输入的身份验证器代码无效。
解决方案
1. 调整CustomUserStore的2FA相关实现
从日志中的IUserAuthenticatorKeyStore_GetAuthenticatorKeyAsync调用可以看出,系统判定用户需要走2FA流程的核心原因是:你的CustomUserStore实现了IUserAuthenticatorKeyStore接口,或存储的用户数据中AuthenticatorKey字段不为空。
- 若暂时不需要2FA,直接移除
IUserAuthenticatorKeyStore接口的实现; - 若必须保留接口,修改
GetAuthenticatorKeyAsync方法返回null,让UserManager判定用户未启用2FA:public Task<string> GetAuthenticatorKeyAsync(TUser user, CancellationToken cancellationToken) { return Task.FromResult<string>(null); }
2. 自定义Login页面的登录逻辑
Default UI的Login页面会自动触发2FA验证跳转,需要将Login页面脚手架到项目中,手动修改登录流程:
- 执行脚手架命令生成Login页面文件:
dotnet aspnet-codegenerator identity -dc ApplicationDbContext --files "Account.Login" - 打开生成的
Login.cshtml.cs,找到OnPostAsync方法,跳过2FA判断逻辑,直接完成登录跳转:var result = await _signInManager.PasswordSignInAsync(Input.Email, Input.Password, Input.RememberMe, lockoutOnFailure: false); if (result.Succeeded) { _logger.LogInformation("用户已登录。"); return LocalRedirect(returnUrl); } // 保留原有的错误处理逻辑(如密码错误、锁定等)
3. 确认Identity全局配置
在Program.cs(或Startup.cs)中配置Identity时,关闭强制验证要求,避免其他触发2FA的逻辑:
builder.Services.AddDefaultIdentity<IdentityUser>(options => { options.SignIn.RequireConfirmedAccount = false; options.SignIn.RequireConfirmedEmail = false; options.SignIn.RequireConfirmedPhoneNumber = false; }) .AddEntityFrameworkStores<ApplicationDbContext>();
内容的提问来源于stack exchange,提问作者user18928007
相关产品推荐
相关产品推荐

