Azure AD OWIN与OpenID Connect认证问题IDX21323:重定向循环求助
First, let's break down what the IDX21323 error means: it typically signals that the OpenID Connect middleware can't properly read or validate the authentication cookie, triggering repeated redirects to login.microsoft.com because the app doesn't recognize a valid authenticated session. Looking at your startup.cs code, there are clear conflicts and misconfigurations driving this loop—let's fix them step by step.
Key Issues in Your Current Setup
Duplicate Cookie Authentication Middleware
You’re callingapp.UseCookieAuthenticationtwice: once with a custom configuration (includingSystemWebChunkingCookieManager) and once with default settings. This creates conflicting cookie handlers, leading to invalid session state and repeated authentication attempts.Potential Authentication Type Misalignment
While you set the default sign-in type to match your custom cookie authentication type, the redundant secondUseCookieAuthenticationcall overrides or disrupts this setup, breaking the cookie validation flow.Unoptimized Cookie Handling
Even withSystemWebChunkingCookieManager, if the authentication cookie exceeds browser size limits (~4KB), chunking might not work as expected, or the cookie isn’t being properly split/stored.
Corrected Startup Configuration
Here’s the cleaned-up Configuration method that resolves these conflicts:
public void Configuration(IAppBuilder app) { // Set default sign-in type to match your cookie authentication type app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType); // Single, configured Cookie Authentication middleware (no duplicates!) app.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = CookieAuthenticationDefaults.AuthenticationType, CookieManager = new SystemWebChunkingCookieManager(), // Optional: Add security and size-related settings CookieName = "YourAppAuthCookie", CookiePath = "/", CookieHttpOnly = true, ExpireTimeSpan = TimeSpan.FromHours(1) }); app.UseOpenIdConnectAuthentication( new OpenIdConnectAuthenticationOptions { ClientId = clientId, Authority = authority, RedirectUri = redirectUri, PostLogoutRedirectUri = redirectUri, Scope = OpenIdConnectScope.OpenIdProfile, ResponseType = OpenIdConnectResponseType.IdToken, TokenValidationParameters = new TokenValidationParameters() { ValidateIssuer = false }, Notifications = new OpenIdConnectAuthenticationNotifications { AuthenticationFailed = OnAuthenticationFailed } } ); }
Additional Troubleshooting Steps
Verify Redirect URI in Azure AD
Ensure theredirectUriin your code exactly matches one of the redirect URIs registered in your Azure AD app registration (including the HTTPS scheme and port number). Mismatched URIs cause silent authentication failures and redirect loops.Inspect Browser Cookies
Use your browser’s dev tools (Application > Cookies) to check the authentication cookie size. If it’s over ~4KB, reduce the amount of data stored in the cookie (e.g., trim excessive claims).Confirm Middleware Order
Make sureUseCookieAuthenticationis called beforeUseOpenIdConnectAuthentication—middleware order is critical, and reversing them breaks the authentication flow.Test with a Clean Session
Stale cookies can cause loops. Clear your browser’s cookies or use incognito mode to test if the issue persists.
内容的提问来源于stack exchange,提问作者Raven Dorado

