You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用HttpClientFactory Typed客户端调用带ValidateAntiForgeryToken的服务端API

解决方案

1. 获取防伪令牌

后端直接获取(完全无需JS)

在MVC项目中注入IAntiforgery和IHttpContextAccessor服务,直接从当前请求上下文生成令牌:

  • 首先确认Program.cs中已注册IHttpContextAccessor:
    builder.Services.AddHttpContextAccessor();
    
  • 在你的Typed HttpClient所在服务/控制器中注入对应服务:
    private readonly IAntiforgery _antiforgery;
    private readonly IHttpContextAccessor _contextAccessor;
    private readonly HttpClient _httpClient;
    
    public YourService(IAntiforgery antiforgery, IHttpContextAccessor contextAccessor, HttpClient httpClient)
    {
        _antiforgery = antiforgery;
        _contextAccessor = contextAccessor;
        _httpClient = httpClient;
    }
    
  • 调用API前生成令牌对:
    var csrfTokens = _antiforgery.GetAndStoreTokens(_contextAccessor.HttpContext);
    

从视图获取(仅需最多1行JS,可完全不用)

在Razor视图中直接调用内置方法生成令牌:

@* 生成隐藏Input,令牌值存储在name为__RequestVerificationToken的元素中 *@
@Html.AntiForgeryToken()

如果需要前端读取令牌,仅需一行JS:

const csrfToken = document.querySelector('input[name="__RequestVerificationToken"]').value;

2. 附加令牌到请求头

方式1:附加到单次请求(推荐,不污染全局配置)

用HttpRequestMessage构造请求,单独加头:

var request = new HttpRequestMessage(HttpMethod.Post, "api/edit/" + id);
request.Content = httpcontent;
// 附加防伪令牌到请求头,默认头名为RequestVerificationToken
request.Headers.Add("RequestVerificationToken", csrfTokens.RequestToken);

var response = await _httpClient.SendAsync(request);
response.EnsureSuccessStatusCode();

方式2:附加到HttpClient全局默认头

适合所有请求都需要传令牌的场景:

_httpClient.DefaultRequestHeaders.Remove("RequestVerificationToken");
_httpClient.DefaultRequestHeaders.Add("RequestVerificationToken", csrfTokens.RequestToken);

// 原有调用逻辑不变
var response = await _httpClient.PostAsync("api/edit/" + id, httpcontent);
response.EnsureSuccessStatusCode();

3. 异常处理配置

如果调用仍提示校验失败,确认API端和客户端的防伪配置一致,在API的Program.cs中添加配置:

builder.Services.AddAntiforgery(options =>
{
    // 保持请求头名称和客户端传递的一致
    options.HeaderName = "RequestVerificationToken";
    // 若跨域调用,需配置Cookie的域名、SameSite属性匹配调用方
    options.Cookie.SameSite = SameSiteMode.Lax;
});

注意:如果API校验逻辑同时匹配Cookie中的防伪值,注册Typed HttpClient时需要启用Cookie支持:

builder.Services.AddHttpClient<YourTypedClient>(client =>
{
    client.BaseAddress = new Uri("你的API服务地址");
}).ConfigurePrimaryHttpMessageHandler(() => new HttpClientHandler
{
    UseCookies = true
});

内容的提问来源于stack exchange,提问作者p2K

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.28 23:15:07