.NET C# MVC项目忘记密码链接跳转至首页而非重置页问题
Hey there, let's work through this issue where your password reset link lands on the home page instead of the reset password form. I've debugged similar MVC problems before, so here are the most likely causes and fixes:
1. Check for [Authorize] Attribute Blocking Access
First, make sure your ResetPassword action allows anonymous users. If your AccountController has a global [Authorize] attribute, or the ResetPassword action itself is marked with [Authorize], MVC will redirect unauthenticated users to the default login route (which might be misconfigured to point to your home page).
Fix this by adding [AllowAnonymous] to the action:
[AllowAnonymous] public ActionResult ResetPassword(string userId, string code) { // Your existing logic here }
2. Inspect the ResetPassword Action Logic for Incorrect Redirects
Take a close look at the code inside your ResetPassword method. A common mistake is redirecting to the home page if userId or code are null/empty, but this can trigger if parameters aren't passed correctly:
[AllowAnonymous] public ActionResult ResetPassword(string userId, string code) { // ❌ This would send users to home if parameters are missing if (string.IsNullOrEmpty(userId) || string.IsNullOrEmpty(code)) { return RedirectToAction("Index", "Home"); } // ✅ Instead, return an error view or keep users in the reset flow // return View("InvalidResetLink"); return View(); }
If this redirect exists, it means your link isn't passing valid userId and code values to the action (we'll cover why next).
3. Fix URL Encoding Issues in the Reset Link
Your provided link uses & instead of & between parameters. This is an HTML-encoded ampersand—while most browsers decode it automatically, some email clients or link generation code might not handle it correctly. This can lead to the code parameter being misnamed (e.g., amp;code instead of code), making it null in the action.
When generating the reset link, avoid double-encoding. If using Razor for email templates, use @Html.Raw() to prevent automatic encoding:
// Generate the correct callback URL in your controller var callbackUrl = Url.Action("ResetPassword", "Account", new { userId = user.Id, code = code }, protocol: Request.Url.Scheme); // In your email view, render it without encoding @Html.Raw(callbackUrl)
4. Verify Route Configuration Conflicts
Check your RouteConfig.cs to ensure no custom routes are intercepting the Account/ResetPassword path. A misconfigured route that maps to the home page could override default controller/action routing:
public static void RegisterRoutes(RouteCollection routes) { routes.IgnoreRoute("{resource}.axd/{*pathInfo}"); // ❌ Avoid routes that might catch Account/ResetPassword // routes.MapRoute( // name: "BadRoute", // url: "Account/{action}", // defaults: new { controller = "Home", action = "Index" } // ); // ✅ Keep the default route (or ensure it's the last one) routes.MapRoute( name: "Default", url: "{controller}/{action}/{id}", defaults: new { controller = "Home", action = "Index", id = UrlParameter.Optional } ); }
Place custom routes after specific account routes, or add constraints to prevent conflicts.
5. Check for Global Action Filters
If you have custom global action filters (e.g., a filter checking user session state), they might redirect users to the home page before the ResetPassword action runs. Review filters registered in Global.asax.cs to ensure they don't block anonymous access to the reset password route.
内容的提问来源于stack exchange,提问作者Hozifa Khater

