You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何控制ASP.NET Core Identity DefaultUI登录后自动重定向至LoginWith2fa?

解决登录后自动重定向到LoginWith2fa的问题

问题背景

自定义UserStore后,用户在/Identity/Account/Login提交登录请求,Default UI会自动重定向到/Identity/Account/LoginWith2fa页面,希望简化用户登录流程,暂时禁用2FA相关的自动跳转逻辑。

日志信息

Microsoft.AspNetCore.Routing.EndpointMiddleware: 信息:正在执行终结点 '/Account/LoginWith2fa'
Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker: 信息:路由匹配成功 {page = "/Account/LoginWith2fa", area = "Identity", action = "", controller = ""}。正在执行页面 /Account/LoginWith2fa
Microsoft.EntityFrameworkCore.Infrastructure: 信息:Entity Framework Core 6.0.7 已初始化 'ApplicationDbContext',使用提供程序 'Pomelo.EntityFrameworkCore.MySql:6.0.2',选项:CommandTimeout=10 ServerVersion 10.5.9-mariadb 
Microsoft.AspNetCore.Mvc.RazorPages.Infrastructure.PageActionInvoker: 信息:正在执行处理程序方法 Microsoft.AspNetCore.Identity.UI.V5.Pages.Account.Internal.LoginWith2faModel.OnPostAsync - ModelState 有效
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByIdAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByIdAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserLockoutStore_GetLockoutEnabledAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserAuthenticatorKeyStore_GetAuthenticatorKeyAsync
Microsoft.AspNetCore.Identity.UserManager: 警告:VerifyTwoFactorTokenAsync() 对用户验证失败。
BackendAPI.Services.CustomUserStore: 信息:456780: IUserLockoutStore_IncrementAccessFailedCountAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserNameAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_FindByNameAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserNameAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_SetNormalizedUserNameAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_UpdateAsync
BackendAPI.Services.CustomUserStore: 信息:456780: IUserStore_GetUserIdAsync
Microsoft.AspNetCore.Identity.UI.V5.Pages.Account.Internal.LoginWith2faModel: 警告:输入的身份验证器代码无效。

解决方案

1. 调整CustomUserStore的2FA相关实现

从日志中的IUserAuthenticatorKeyStore_GetAuthenticatorKeyAsync调用可以看出,系统判定用户需要走2FA流程的核心原因是:你的CustomUserStore实现了IUserAuthenticatorKeyStore接口,或存储的用户数据中AuthenticatorKey字段不为空。

  • 若暂时不需要2FA,直接移除IUserAuthenticatorKeyStore接口的实现;
  • 若必须保留接口,修改GetAuthenticatorKeyAsync方法返回null,让UserManager判定用户未启用2FA:
    public Task<string> GetAuthenticatorKeyAsync(TUser user, CancellationToken cancellationToken)
    {
        return Task.FromResult<string>(null);
    }
    

2. 自定义Login页面的登录逻辑

Default UI的Login页面会自动触发2FA验证跳转,需要将Login页面脚手架到项目中,手动修改登录流程:

  1. 执行脚手架命令生成Login页面文件:
    dotnet aspnet-codegenerator identity -dc ApplicationDbContext --files "Account.Login"
    
  2. 打开生成的Login.cshtml.cs,找到OnPostAsync方法,跳过2FA判断逻辑,直接完成登录跳转:
    var result = await _signInManager.PasswordSignInAsync(Input.Email, Input.Password, Input.RememberMe, lockoutOnFailure: false);
    if (result.Succeeded)
    {
        _logger.LogInformation("用户已登录。");
        return LocalRedirect(returnUrl);
    }
    // 保留原有的错误处理逻辑(如密码错误、锁定等)
    

3. 确认Identity全局配置

在Program.cs(或Startup.cs)中配置Identity时,关闭强制验证要求,避免其他触发2FA的逻辑:

builder.Services.AddDefaultIdentity<IdentityUser>(options => 
{
    options.SignIn.RequireConfirmedAccount = false;
    options.SignIn.RequireConfirmedEmail = false;
    options.SignIn.RequireConfirmedPhoneNumber = false;
})
.AddEntityFrameworkStores<ApplicationDbContext>();

内容的提问来源于stack exchange,提问作者user18928007

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 12:24:24