Microsoft.Identity.Web是否支持带aspx页面的ASP.NET Web应用?如何注册认证
ASP.NET Web Forms(aspx页面)Azure AD B2C身份认证配置说明
首先明确:Microsoft.Identity.Web 是专门为ASP.NET Core生态设计的身份类库,不支持基于.NET Framework的传统ASP.NET Web Forms(使用.aspx页面的应用),你无法直接在Web Forms项目中复用AddMicrosoftIdentityWebApp这类.NET Core专属的依赖注入配置方法。
如果要在Web Forms项目中实现和.NET Core端一致的Azure AD B2C身份认证逻辑,可以通过OWIN中间件完成配置,步骤如下:
- 第一步:通过NuGet安装适配.NET Framework的依赖包,分别是
Microsoft.Owin.Security.OpenIdConnect、Microsoft.Owin.Security.Cookies、Microsoft.Owin.Host.SystemWeb - 第二步:在项目根目录新增OWIN启动类
Startup.cs,编写认证配置逻辑:
using Microsoft.Owin; using Owin; using Microsoft.IdentityModel.Protocols.OpenIdConnect; using Microsoft.Owin.Security; using Microsoft.Owin.Security.Cookies; using Microsoft.Owin.Security.OpenIdConnect; using System.Configuration; // 替换为你项目的实际命名空间 [assembly: OwinStartup(typeof(WebFormsDemo.Startup))] namespace WebFormsDemo { public class Startup { public void Configuration(IAppBuilder app) { // 配置Cookie认证,对应.NET Core配置中的"cookiesB2C"方案 app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType); app.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = "cookiesB2C", CookieName = "B2CAuthCookie" }); // 配置Azure AD B2C OpenIdConnect认证,对应.NET Core配置中的"b2c"方案 app.UseOpenIdConnectAuthentication(new OpenIdConnectAuthenticationOptions { AuthenticationType = "b2c", MetadataAddress = $"https://{ConfigurationManager.AppSettings["AzureAdB2C:TenantName"]}.b2clogin.com/{ConfigurationManager.AppSettings["AzureAdB2C:TenantName"]}.onmicrosoft.com/{ConfigurationManager.AppSettings["AzureAdB2C:PolicyId"]}/v2.0/.well-known/openid-configuration", ClientId = ConfigurationManager.AppSettings["AzureAdB2C:ClientId"], RedirectUri = ConfigurationManager.AppSettings["AzureAdB2C:RedirectUri"], PostLogoutRedirectUri = ConfigurationManager.AppSettings["AzureAdB2C:PostLogoutRedirectUri"], ResponseType = OpenIdConnectResponseType.CodeIdToken, Scope = $"openid offline_access {ConfigurationManager.AppSettings["AzureAdB2C:ClientId"]}", TokenValidationParameters = new Microsoft.IdentityModel.Tokens.TokenValidationParameters { NameClaimType = "name" } }); } } }
- 第三步:在
Web.config的appSettings节点添加B2C配置项:
<appSettings> <add key="AzureAdB2C:TenantName" value="你的B2C租户名称" /> <add key="AzureAdB2C:ClientId" value="Azure门户中应用注册的客户端ID" /> <add key="AzureAdB2C:PolicyId" value="你的注册登录用户流ID" /> <add key="AzureAdB2C:RedirectUri" value="你的应用回调地址,比如https://localhost:44300/" /> <add key="AzureAdB2C:PostLogoutRedirectUri" value="登出后跳转地址" /> </appSettings>
- 第四步:配置全局/页面级认证规则
如果需要全站要求登录,在Web.config的system.web节点添加如下配置:
如果只需要给特定aspx页面加认证拦截,直接在对应页面的<system.web> <authorization> <deny users="?" /> </authorization> <authentication mode="None" /> </system.web>Page_Load事件中添加判断即可:
登出逻辑示例:protected void Page_Load(object sender, EventArgs e) { if (!Request.IsAuthenticated) { // 触发B2C登录流程 HttpContext.Current.GetOwinContext().Authentication.Challenge( new AuthenticationProperties { RedirectUri = "/" }, "b2c"); } }protected void Logout_Click(object sender, EventArgs e) { if (Request.IsAuthenticated) { HttpContext.Current.GetOwinContext().Authentication.SignOut( CookieAuthenticationDefaults.AuthenticationType, "b2c"); } }
内容的提问来源于stack exchange,提问作者chindirala sampath kumar
相关产品推荐
相关产品推荐

