ASP.NET 4.5应用中Swagger UI访问跳转登录页的问题求助
Hey there! Let's break down why your Swagger UI is redirecting to the login page and how to fix it. I’ve dealt with this exact issue a few times with ASP.NET 4.5 Web API and Swashbuckle, so here’s what to check step by step:
The most common culprit is a global authorization rule that blocks anonymous access to all paths—including Swagger.
Open your Web.config and look for a section like this:
<system.web> <authorization> <deny users="?" /> <!-- This blocks all unauthenticated users --> </authorization> </system.web>
If that exists, add location-specific rules to allow anonymous access to Swagger paths:
<!-- Allow unauthenticated access to Swagger root --> <location path="swagger"> <system.web> <authorization> <allow users="*" /> </authorization> </system.web> </location> <!-- Allow unauthenticated access to Swagger UI --> <location path="swagger/ui"> <system.web> <authorization> <allow users="*" /> </authorization> </system.web> </location>
If you added a global AuthorizeAttribute to your Web API, it might be intercepting Swagger requests too.
Check your WebApiConfig.cs or SwaggerConfig.cs for a line like:
GlobalConfiguration.Configuration.Filters.Add(new AuthorizeAttribute());
If so, replace it with a custom authorization filter that skips Swagger paths:
public class SkipSwaggerAuthorizeAttribute : AuthorizeAttribute { public override void OnAuthorization(HttpActionContext actionContext) { var requestPath = actionContext.Request.RequestUri.PathAndQuery; // Bypass authorization for all Swagger-related endpoints if (requestPath.StartsWith("/swagger", StringComparison.OrdinalIgnoreCase)) { return; } base.OnAuthorization(actionContext); } }
Then update the global filter to use your custom attribute:
GlobalConfiguration.Configuration.Filters.Add(new SkipSwaggerAuthorizeAttribute());
If you’re using IIS, make sure no URL rewrite rules are accidentally redirecting Swagger requests to the login page. Look in Web.config for a <rewrite> section and verify none of the rules target /swagger or /swagger/ui.
While less likely, double-check your AngularJS 1.5.4 routing config to ensure there’s no route that matches /swagger and redirects to login. Test accessing the full Swagger UI URL directly: localhost:9000/swagger/ui/index—if it still redirects, the issue is definitely on the backend.
Old versions of Swashbuckle can have compatibility issues with ASP.NET 4.5 Web API. Ensure you’re using a version that supports .NET 4.5 (typically Swashbuckle.Core 5.x series). If needed, update the NuGet package:
Update-Package Swashbuckle.Core
If none of these fix the issue, sharing these details will help narrow it down:
- Snippets of your
Web.config(authorization/authentication sections) - Full code from
SwaggerConfig.cs - Any custom authentication/authorization frameworks you’re using (e.g., ASP.NET Identity, OAuth2)
- Which component is triggering the login redirect (Forms Auth, custom filter, etc.)
内容的提问来源于stack exchange,提问作者Nathan Pena

