You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET C# MVC项目忘记密码链接跳转至首页而非重置页问题

Hey there, let's work through this issue where your password reset link lands on the home page instead of the reset password form. I've debugged similar MVC problems before, so here are the most likely causes and fixes:

1. Check for [Authorize] Attribute Blocking Access

First, make sure your ResetPassword action allows anonymous users. If your AccountController has a global [Authorize] attribute, or the ResetPassword action itself is marked with [Authorize], MVC will redirect unauthenticated users to the default login route (which might be misconfigured to point to your home page).

Fix this by adding [AllowAnonymous] to the action:

[AllowAnonymous]
public ActionResult ResetPassword(string userId, string code)
{
    // Your existing logic here
}

2. Inspect the ResetPassword Action Logic for Incorrect Redirects

Take a close look at the code inside your ResetPassword method. A common mistake is redirecting to the home page if userId or code are null/empty, but this can trigger if parameters aren't passed correctly:

[AllowAnonymous]
public ActionResult ResetPassword(string userId, string code)
{
    // ❌ This would send users to home if parameters are missing
    if (string.IsNullOrEmpty(userId) || string.IsNullOrEmpty(code))
    {
        return RedirectToAction("Index", "Home"); 
    }

    // ✅ Instead, return an error view or keep users in the reset flow
    // return View("InvalidResetLink");
    return View();
}

If this redirect exists, it means your link isn't passing valid userId and code values to the action (we'll cover why next).

Your provided link uses & instead of & between parameters. This is an HTML-encoded ampersand—while most browsers decode it automatically, some email clients or link generation code might not handle it correctly. This can lead to the code parameter being misnamed (e.g., amp;code instead of code), making it null in the action.

When generating the reset link, avoid double-encoding. If using Razor for email templates, use @Html.Raw() to prevent automatic encoding:

// Generate the correct callback URL in your controller
var callbackUrl = Url.Action("ResetPassword", "Account", 
    new { userId = user.Id, code = code }, 
    protocol: Request.Url.Scheme);

// In your email view, render it without encoding
@Html.Raw(callbackUrl)

4. Verify Route Configuration Conflicts

Check your RouteConfig.cs to ensure no custom routes are intercepting the Account/ResetPassword path. A misconfigured route that maps to the home page could override default controller/action routing:

public static void RegisterRoutes(RouteCollection routes)
{
    routes.IgnoreRoute("{resource}.axd/{*pathInfo}");

    // ❌ Avoid routes that might catch Account/ResetPassword
    // routes.MapRoute(
    //     name: "BadRoute",
    //     url: "Account/{action}",
    //     defaults: new { controller = "Home", action = "Index" }
    // );

    // ✅ Keep the default route (or ensure it's the last one)
    routes.MapRoute(
        name: "Default",
        url: "{controller}/{action}/{id}",
        defaults: new { controller = "Home", action = "Index", id = UrlParameter.Optional }
    );
}

Place custom routes after specific account routes, or add constraints to prevent conflicts.

5. Check for Global Action Filters

If you have custom global action filters (e.g., a filter checking user session state), they might redirect users to the home page before the ResetPassword action runs. Review filters registered in Global.asax.cs to ensure they don't block anonymous access to the reset password route.


内容的提问来源于stack exchange,提问作者Hozifa Khater

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:40:20