You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core中Web与Ionic移动端ADFS认证配置问题咨询

Fixing Ionic Mobile Authentication with ADFS for ASP.NET Core Web API

Hey there! Let's tackle your mobile authentication issue head-on. The core problem right now is that your Web API is falling back to the web-oriented OAuth/Cookie flow when presented with a Bearer token, leading to that unwanted redirect to the ADFS login page. Here's how to fix it step by step:

1. Understand the Root Cause

Your current setup sets global default authentication schemes to Cookie/OAuth (for web browsers), so when your Ionic app sends a Bearer token, the API tries to authenticate with cookies first, fails, and triggers a browser-friendly OAuth redirect instead of validating the JWT token properly. We need to split the authentication logic for web vs. mobile/API clients.

2. Configure JwtBearer for ADFS Correctly

Stop using an empty OpenIdConnectConfiguration—point the JwtBearer middleware directly to your ADFS instance's metadata endpoint, which publishes all the necessary token validation details.

Update your AddJwtBearer section in Startup.cs:

.AddJwtBearer("Bearer", options =>
{
    options.Authority = "https://your-adfs-server/adfs";
    options.Audience = "your-api-resource-identifier"; // Match the relying party trust name you set up in ADFS for your API
    options.MetadataAddress = "https://your-adfs-server/adfs/.well-known/openid-configuration";
    
    // Lock down token validation
    options.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuer = true,
        ValidIssuer = "http://your-adfs-server/adfs/services/trust", // Grab this value from your ADFS metadata
        ValidateAudience = true,
        ValidAudience = "your-api-resource-identifier",
        ValidateLifetime = true,
        ClockSkew = TimeSpan.Zero // Strict expiration check
    };
})

3. Separate Authentication Schemes for Web vs. API

Remove global default scheme settings, and use explicit scheme requirements for each controller type:

Update Authentication Setup

services.AddAuthentication()
    .AddOAuth(OAuthDefaults.DisplayName, options =>
    {
        // Keep your existing web client OAuth configuration here (the one that works for browsers)
    })
    .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddJwtBearer("Bearer", options =>
    {
        // The JwtBearer config from step 2 goes here
    });

Apply Schemes to Controllers

  • For your web controller (browser-only), explicitly require the cookie scheme:
    [Authorize(AuthenticationSchemes = CookieAuthenticationDefaults.AuthenticationScheme)]
    public class MyWebController : Controller
    {
        // Your web controller code
    }
    
  • For your API controller (mobile/API clients), require the Bearer scheme:
    [Route("api/[controller]")]
    [Produces("application/json")]
    [ApiController]
    [Authorize(AuthenticationSchemes = "Bearer")]
    public class MyApiController : ControllerBase
    {
        // Your API controller code
    }
    

If you have multiple API controllers, create a global policy to avoid repeating the annotation:

services.AddMvc(options =>
{
    var apiAuthPolicy = new AuthorizationPolicyBuilder("Bearer")
        .RequireAuthenticatedUser()
        .Build();
    options.Filters.Add(new AuthorizeFilter(apiAuthPolicy));
})
.SetCompatibilityVersion(CompatibilityVersion.Version_2_2);

4. Enable Resource Owner Password Credentials (ROPC) Flow in ADFS

To let your Ionic app send a username/password directly to get a Bearer token, you need to enable the ROPC flow for your API's relying party trust in ADFS:

  1. In ADFS Management, go to Relying Party Trusts > Select your API trust > Properties > Advanced > Check Allow OAuth Implicit Flow.
  2. Use PowerShell to explicitly enable ROPC:
    Set-AdfsRelyingPartyTrust -TargetName "Your API Relying Party" -AllowedOAuthFlows "AuthorizationCode", "RefreshToken", "ResourceOwnerPassword"
    
  3. Ensure your claim rules issue the necessary tokens (like sub, name) for the API.

5. Ionic App Token Request Example

Your Ionic app should send a POST request to ADFS's token endpoint with form data to retrieve a Bearer token:

const tokenEndpoint = 'https://your-adfs-server/adfs/oauth2/token';
const formData = new FormData();

formData.append('grant_type', 'password');
formData.append('client_id', 'your-ionic-client-id'); // Match the client ID in your ADFS relying party
formData.append('username', 'user@your-domain.com');
formData.append('password', 'user-password');
formData.append('resource', 'your-api-resource-identifier'); // Same as the Audience in JwtBearer config

// Fetch token and use it for API requests
this.http.post(tokenEndpoint, formData).subscribe(tokenResponse => {
    const accessToken = tokenResponse['access_token'];
    
    this.http.get('https://your-api-url/api/MyApi', {
        headers: { 'Authorization': `Bearer ${accessToken}` }
    }).subscribe(apiResponse => {
        // Handle your API data here
    });
});

6. Verify CORS Configuration

Your existing CORS policy looks okay, but double-check it allows the Authorization header (critical for Bearer tokens):

services.AddCors(x => x.AddPolicy("corsGlobalPolicy", policy =>
{
    policy.AllowAnyHeader();
    policy.AllowAnyMethod();
    policy.AllowAnyOrigin();
    policy.AllowCredentials();
}));

Don't forget to apply the policy in your Configure method:

app.UseCors("corsGlobalPolicy");

Final Checks

  • Decode the token from Ionic using a tool like jwt.io to confirm the issuer, audience, and claims match your API's configuration.
  • Ensure unauthenticated API requests return a 401 Unauthorized instead of a redirect (this confirms the Bearer scheme is working).
  • Verify ADFS is issuing tokens for your API's resource identifier.

内容的提问来源于stack exchange,提问作者Esteban Silva

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.14 07:01:32