You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何将ASP.NET WebAPI的ClaimsPrincipal转发至另一WebAPI

实现ASP.NET WebAPI间的ClaimsPrincipal转发

1. 在调用方(第一个WebAPI)中传递身份信息

发起对第二个WebAPI的请求时,需将当前ClaimsPrincipal的身份信息传递过去,常用两种方案:

方案A:复用JWT令牌传递

若第一个WebAPI本身基于JWT认证,直接复用当前请求的JWT令牌即可:

// 从当前请求头获取JWT令牌
var token = HttpContext.Request.Headers["Authorization"].FirstOrDefault()?.Replace("Bearer ", "");
using var client = new HttpClient();
// 将令牌添加到目标API的请求头
client.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", token);
var response = await client.GetAsync("https://目标API地址/接口路径");

方案B:自定义请求头传递关键Claims

如果不需要完整JWT,可提取核心Claims(如用户ID、用户名)放到自定义请求头中:

// 从当前ClaimsPrincipal提取关键信息
var userId = HttpContext.User.FindFirst(ClaimTypes.NameIdentifier)?.Value;
var userName = HttpContext.User.FindFirst(ClaimTypes.Name)?.Value;

using var client = new HttpClient();
// 添加自定义请求头
client.DefaultRequestHeaders.Add("X-User-Id", userId);
client.DefaultRequestHeaders.Add("X-User-Name", userName);
var response = await client.GetAsync("https://目标API地址/接口路径");

2. 在接收方(第二个WebAPI)中还原ClaimsPrincipal

根据传递方式,在第二个WebAPI中解析身份信息并构建ClaimsPrincipal:

对应方案A:配置JWT认证解析

给第二个WebAPI添加JWT认证配置(无需强制验证,仅解析有效令牌):

  1. 安装Microsoft.AspNetCore.Authentication.JwtBearer包
  2. 在Program.cs中配置认证服务:
builder.Services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
    .AddJwtBearer(options =>
    {
        options.TokenValidationParameters = new TokenValidationParameters
        {
            ValidateIssuer = true,
            ValidateAudience = true,
            ValidateLifetime = true,
            ValidateIssuerSigningKey = true,
            ValidIssuer = "第一个API的Issuer", // 与调用方配置一致
            ValidAudience = "第一个API的Audience", // 与调用方配置一致
            IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes("密钥字符串")) // 与调用方配置一致
        };
        // 令牌无效时不拦截请求,保持匿名状态
        options.Events = new JwtBearerEvents
        {
            OnAuthenticationFailed = context =>
            {
                context.SkipToNextMiddleware();
                return Task.CompletedTask;
            }
        };
    });

// 启用认证中间件
app.UseAuthentication();
app.UseAuthorization();

配置完成后,若请求携带有效JWT,HttpContext.User会自动填充为ClaimsPrincipal。

对应方案B:自定义中间件还原Claims

编写中间件读取自定义请求头并构建ClaimsPrincipal:

  1. 创建中间件类:
public class ClaimsForwardMiddleware
{
    private readonly RequestDelegate _next;

    public ClaimsForwardMiddleware(RequestDelegate next)
    {
        _next = next;
    }

    public async Task InvokeAsync(HttpContext context)
    {
        var userId = context.Request.Headers["X-User-Id"].FirstOrDefault();
        var userName = context.Request.Headers["X-User-Name"].FirstOrDefault();

        if (!string.IsNullOrEmpty(userId))
        {
            var claims = new List<Claim>
            {
                new Claim(ClaimTypes.NameIdentifier, userId),
                new Claim(ClaimTypes.Name, userName ?? "")
            };
            var identity = new ClaimsIdentity(claims, "ForwardedAuth");
            context.User = new ClaimsPrincipal(identity);
        }

        await _next(context);
    }
}
  1. 在Program.cs中注册中间件(需放在UseAuthorization之前):
app.UseMiddleware<ClaimsForwardMiddleware>();
app.UseAuthorization();

3. 注意事项

  • 传递敏感信息时必须使用HTTPS加密,防止数据泄露
  • 自定义请求头尽量避免传递过多信息,只保留业务必需的用户标识
  • 第二个WebAPI需确保匿名访问仍被允许,仅在存在身份信息时填充User

内容的提问来源于stack exchange,提问作者BennoDual

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.23 02:45:21