You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core MVC认证后,如何向REST API端点传递已登录用户信息?

从ASP.NET Core MVC调用REST API并传递已登录用户信息的方案

下面是几个在实际项目中常用的实现方式,你可以根据自己的部署场景和认证体系选最合适的:

1. 传递JWT访问令牌(通用跨域/独立服务场景)

如果你的REST API是基于JWT认证的,这是最标准的做法。核心逻辑就是从MVC应用的HttpContext里拿到当前登录用户的JWT令牌,再通过Authorization请求头传递给API。

实现步骤:

  • 确保MVC应用已经配置了JWT相关的认证(比如用IdentityServer、Azure AD或者自定义JWT认证),用户登录后令牌会存在HttpContext中。
  • 在MVC的控制器或服务里注入IHttpClientFactory,用来创建调用API的HttpClient实例。
  • 从HttpContext获取访问令牌,添加到请求头里。

代码示例:

// MVC中的服务/控制器示例
private readonly IHttpClientFactory _httpClientFactory;
private readonly IHttpContextAccessor _httpContextAccessor;

public UserApiService(IHttpClientFactory httpClientFactory, IHttpContextAccessor httpContextAccessor)
{
    _httpClientFactory = httpClientFactory;
    _httpContextAccessor = httpContextAccessor;
}

public async Task<UserProfile> GetUserProfileAsync()
{
    var apiClient = _httpClientFactory.CreateClient("MyRestApi");
    
    // 获取当前用户的JWT访问令牌
    var accessToken = await _httpContextAccessor.HttpContext.GetTokenAsync("access_token");
    if (!string.IsNullOrWhiteSpace(accessToken))
    {
        apiClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
    }
    
    // 调用API端点
    var response = await apiClient.GetAsync("/api/user/profile");
    response.EnsureSuccessStatusCode();
    return await response.Content.ReadFromJsonAsync<UserProfile>();
}

2. Cookie共享(同域/信任子域场景)

如果MVC应用和REST API部署在同一个域名下(或者属于信任的子域),可以通过共享Cookie的方式让API直接识别已登录用户,不用手动传递令牌,Cookie会自动随请求发送。

实现步骤:

  • 给两个应用配置相同的DataProtection密钥,确保Cookie能被彼此解密。
  • 两个应用都启用Cookie认证,并且使用相同的认证Scheme和Cookie名称。

代码示例:

MVC应用的Program.cs配置:

builder.Services.AddDataProtection()
    .SetApplicationName("MySharedApp") // 两个应用必须用同一个名称
    .PersistKeysToFileSystem(new DirectoryInfo(@"D:\SharedAuthKeys")); // 共享密钥的存储目录

builder.Services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddCookie(options =>
    {
        options.Cookie.Name = ".MyApp.AuthCookie"; // 两个应用的Cookie名称要一致
        options.Cookie.Domain = ".mycompany.com"; // 跨子域的话设置根域名
    });

REST API应用的Program.cs配置:

builder.Services.AddDataProtection()
    .SetApplicationName("MySharedApp")
    .PersistKeysToFileSystem(new DirectoryInfo(@"D:\SharedAuthKeys"));

builder.Services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
    .AddCookie(options =>
    {
        options.Cookie.Name = ".MyApp.AuthCookie";
        options.Cookie.Domain = ".mycompany.com";
    });

// 确保API端点需要认证
app.UseAuthorization();
app.MapControllers().RequireAuthorization();

3. 自定义HttpMessageHandler自动传递身份(优雅封装场景)

如果项目中需要频繁调用API,可以封装一个自定义的DelegatingHandler,自动把当前用户的令牌添加到请求头,避免重复写添加令牌的代码。

代码示例:

自定义认证Handler:

public class AuthTokenHandler : DelegatingHandler
{
    private readonly IHttpContextAccessor _httpContextAccessor;

    public AuthTokenHandler(IHttpContextAccessor httpContextAccessor)
    {
        _httpContextAccessor = httpContextAccessor;
    }

    protected override async Task<HttpResponseMessage> SendAsync(HttpRequestMessage request, CancellationToken cancellationToken)
    {
        var accessToken = await _httpContextAccessor.HttpContext.GetTokenAsync("access_token");
        if (!string.IsNullOrWhiteSpace(accessToken))
        {
            request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
        }
        return await base.SendAsync(request, cancellationToken);
    }
}

在MVC的Program.cs注册:

builder.Services.AddTransient<AuthTokenHandler>();

builder.Services.AddHttpClient("MyRestApi", client =>
{
    client.BaseAddress = new Uri("https://myapi.mycompany.com/");
})
.AddHttpMessageHandler<AuthTokenHandler>();

之后每次用"MyRestApi"这个HttpClient调用API时,都会自动带上当前用户的令牌,不用再手动处理了。

补充:Windows认证场景(企业内部局域网)

如果是企业内部应用,用Windows认证的话,只需要让HttpClient使用默认凭据即可:

var client = new HttpClient(new HttpClientHandler { UseDefaultCredentials = true });
var response = await client.GetAsync("https://internal-api.mycompany.com/api/employees");

内容的提问来源于stack exchange,提问作者Szybki

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:09:38