You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD认证登出后,捕获的旧请求仍可正常访问问题咨询

Fixing Azure AD Logout Replay Issue: Old Requests Still Work After Logout

Got it, let's tackle this logout replay issue you're seeing with Azure AD authentication. The core problem here is that while your browser clears session cookies after logout, the server isn't properly invalidating existing sessions or auth tokens—so replaying old requests with captured cookies still gets a valid response. Let's break down the fixes step by step:

1. Replace Session.RemoveAll() with Session.Abandon()

Session.RemoveAll() only clears the key-value pairs stored in the session, but the session ID itself remains valid on the server. When an old request with that session ID comes in, the server will recreate the session (empty, but still recognized as valid). Instead:

// Destroy the server-side session entirely
Session.Abandon();

This tells the server to invalidate the session ID, so any future requests using that ID will be treated as a new, unauthenticated session.

2. Enhance the SignOut Logic & Invalidate Client-Side Cookies

Your current SignOut call clears client-side cookies, but we need to explicitly expire any remaining cookies in the response to prevent clients from reusing them. Update your logout method:

public ActionResult Logout()
{
    // Destroy the server session
    Session.Abandon();

    // Sign out of both OpenID Connect and cookie auth
    var authManager = HttpContext.GetOwinContext().Authentication;
    authManager.SignOut(
        OpenIdConnectAuthenticationDefaults.AuthenticationType,
        CookieAuthenticationDefaults.AuthenticationType);

    // Force all cookies to expire immediately
    foreach (var cookieName in Request.Cookies.AllKeys)
    {
        var cookie = Response.Cookies[cookieName];
        cookie.Expires = DateTime.Now.AddDays(-1);
        cookie.Value = string.Empty;
        cookie.Path = "/"; // Ensure the entire domain path is covered
    }

    return RedirectToAction("Index", "Home");
}

3. Configure OWIN Auth to Validate Tokens on Every Request

By default, some OWIN auth setups only validate tokens during login. We need to add per-request validation to catch expired or invalidated tokens. Update your Startup.cs ConfigureAuth method:

app.UseCookieAuthentication(new CookieAuthenticationOptions
{
    AuthenticationType = CookieAuthenticationDefaults.AuthenticationType,
    ExpireTimeSpan = TimeSpan.FromMinutes(30), // Shorten session lifetime for added security
    SlidingExpiration = true, // Extend session only if user is active
    CookieHttpOnly = true, // Prevent client-side JS access to cookies
    CookieSecure = CookieSecureOption.Always, // Only send cookies over HTTPS
    Provider = new CookieAuthenticationProvider
    {
        OnValidateIdentity = context =>
        {
            var currentUtc = DateTimeOffset.UtcNow;
            // Reject the identity if the token has expired
            if (context.Properties.ExpiresUtc.HasValue && context.Properties.ExpiresUtc.Value < currentUtc)
            {
                context.RejectIdentity();
                context.SignOut(context.Options.AuthenticationType);
            }
            return Task.CompletedTask;
        }
    }
});

OpenID Connect Configuration

Add strict token validation and trigger Azure AD global logout to invalidate the AD-side session:

app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions
{
    ClientId = "<your-client-id>",
    Authority = "https://login.microsoftonline.com/<your-tenant-id>/v2.0",
    RedirectUri = "<your-redirect-uri>",
    PostLogoutRedirectUri = "<your-post-logout-uri>",
    TokenValidationParameters = new TokenValidationParameters
    {
        ValidateLifetime = true, // Enforce token expiry checks
        ClockSkew = TimeSpan.Zero // No tolerance for clock drift (strict validation)
    },
    Notifications = new OpenIdConnectAuthenticationNotifications
    {
        RedirectToIdentityProvider = n =>
        {
            // When logging out, send the ID token hint to Azure AD to invalidate their session
            if (n.ProtocolMessage.RequestType == OpenIdConnectRequestType.Logout)
            {
                var idToken = n.OwinContext.Authentication.User.FindFirst("id_token")?.Value;
                if (!string.IsNullOrEmpty(idToken))
                {
                    n.ProtocolMessage.IdTokenHint = idToken;
                }
            }
            return Task.CompletedTask;
        }
    }
});

4. Additional Security Best Practices

  • Enable CSRF Protection: Ensure all authenticated requests have valid CSRF tokens to block replay attacks even if cookies are captured.
  • Avoid Persistent Cookies: Set IsPersistent = false in your auth properties unless users explicitly request "remember me"—this limits cookie lifetime to the browser session.
  • Shorten Token Expiry: Reduce the ExpireTimeSpan to minimize the window where a captured cookie can be replayed.

With these changes, when a user logs out:

  1. The server destroys the session entirely
  2. All auth cookies are expired on the client
  3. Every subsequent request (even replayed ones) will have their tokens validated, and expired/invalid tokens will be rejected
  4. Azure AD also invalidates the user's session, preventing silent re-authentication

内容的提问来源于stack exchange,提问作者Rahul Shukla

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 05:21:27