You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core 9集成Entra ID后前端通道登出失效问题

ASP.NET Core 9集成Azure Entra ID登出后Cookie/Token未失效问题

环境与配置

  • 基于ASP.NET Core 9构建的应用,集成Azure Entra ID,遵循官方教程配置
  • Azure Entra ID中已设置前端通道登出URL为https://localhost:7114/signout-oidc
  • Entra ID注入代码如下:
public static void InjectEntraID(
        this WebApplicationBuilder builder,
        IConfigurationRoot config,
        [CallerMemberName] string caller = "")
{
    IEnumerable<string>? initialScopes = builder
            .Configuration["DownstreamApi:Scopes"]
            ?.Split(' ');

    builder
        .Services.AddMicrosoftIdentityWebAppAuthentication(builder.Configuration, "EntraID")
        .EnableTokenAcquisitionToCallDownstreamApi(initialScopes)
        .AddDownstreamApi(
                "DownstreamApi",
                builder.Configuration.GetSection("DownstreamApi")
            )
        .AddInMemoryTokenCaches();
}

public static void InjectAspNet(
    this WebApplicationBuilder builder,
    IConfigurationRoot config,
    [CallerMemberName] string caller = "")
{
    // Add services to the container.
    builder
        .Services.AddRazorPages()
            .AddMvcOptions(options =>
            {
                var policy = new AuthorizationPolicyBuilder()
                    .RequireAuthenticatedUser()
                    .Build();
                options.Filters.Add(new AuthorizeFilter(policy));
            })
            .AddMicrosoftIdentityUI()
            .AddMvcLocalization()
            .AddViewLocalization()
            .AddDataAnnotationsLocalization();

    builder.Services.AddSignalR(e =>
        {
            e.EnableDetailedErrors = true;
            e.MaximumReceiveMessageSize = 102400000;
        });
}

问题现象

登出操作完成后,用户的Cookie/Token仍保持有效,可继续通过携带Cookie的请求访问需要身份验证的接口。复现步骤:

  • 调用需用户身份的Ajax接口,将请求转为CURL命令
  • 将CURL导入Postman等工具执行,请求仍能成功返回数据

示例CURL命令:

curl --location 'https://localhost:7114/XXX?handler=AllFiles&sessionId=75dd1c26-19c3-44c6-ad2f-b548a959e042&sessionLang=en-US&instance=dev&searchQuery=' \
--header 'accept: application/json, text/javascript, */*; q=0.01' \
--header 'accept-language: en-US,en;q=0.9' \
--header 'priority: u=1, i' \
--header 'referer: https://localhost:7114/XXX?instance=dev&culture=en-US&sessionId=75dd1c26-19c3-44c6-ad2f-b548a959e042' \
--header 'requestverificationtoken: CfDJ8GQXXXXXXXXXX.......' \
--header 'sec-ch-ua: "Google Chrome";v="141", "Not?A_Brand";v="8", "Chromium";v="141"' \
--header 'sec-ch-ua-mobile: ?0' \
--header 'sec-ch-ua-platform: "macOS"' \
--header 'sec-fetch-dest: empty' \
--header 'sec-fetch-mode: cors' \
--header 'sec-fetch-site: same-origin' \
--header 'Cookie: acknowledged-Terms of Use-1.0=true; .AspNetCore.Cookies=chunks-2; .AspNetCore.CookiesC1=CfDoYbp.........; .AspNetCore.CookiesC2=7LEbP2J.........'

已确认的行为

通过客户端网络日志和ASP.NET Core终端日志确认:

  • Azure已发起远程登出调用
  • 已成功触发signout-callback-oidc请求,请求详情如下:
curl 'https://localhost:7114/signout-callback-oidc?state=CfDJ8GQMaRK5om......' \
  -H 'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7' \
  -H 'accept-language: en-US,en;q=0.9' \
  -b 'acknowledged-Terms of Use-1.0=true' \
  -H 'priority: u=0, i' \
  -H 'referer: https://login.microsoftonline.com/' \
  -H 'sec-ch-ua: "Google Chrome";v="141", "Not?A_Brand";v="8", "Chromium";v="141"' \
  -H 'sec-ch-ua-mobile: ?0' \
  -H 'sec-ch-ua-platform: "macOS"' \
  -H 'sec-fetch-dest: document' \
  -H 'sec-fetch-mode: navigate' \
  -H 'sec-fetch-site: cross-site' \
  -H 'upgrade-insecure-requests: 1' \
  -H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36'

预期结果

根据官方文档,登出后服务器应清除缓存中的Token,使Cookie失效,无法再通过携带Cookie的请求访问需要身份验证的接口。

内容的提问来源于stack exchange,提问作者Imran Sh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.12 05:40:06