ASP.NET Core 9集成Entra ID后前端通道登出失效问题
环境与配置
- 基于ASP.NET Core 9构建的应用,集成Azure Entra ID,遵循官方教程配置
- Azure Entra ID中已设置前端通道登出URL为
https://localhost:7114/signout-oidc - Entra ID注入代码如下:
public static void InjectEntraID( this WebApplicationBuilder builder, IConfigurationRoot config, [CallerMemberName] string caller = "") { IEnumerable<string>? initialScopes = builder .Configuration["DownstreamApi:Scopes"] ?.Split(' '); builder .Services.AddMicrosoftIdentityWebAppAuthentication(builder.Configuration, "EntraID") .EnableTokenAcquisitionToCallDownstreamApi(initialScopes) .AddDownstreamApi( "DownstreamApi", builder.Configuration.GetSection("DownstreamApi") ) .AddInMemoryTokenCaches(); } public static void InjectAspNet( this WebApplicationBuilder builder, IConfigurationRoot config, [CallerMemberName] string caller = "") { // Add services to the container. builder .Services.AddRazorPages() .AddMvcOptions(options => { var policy = new AuthorizationPolicyBuilder() .RequireAuthenticatedUser() .Build(); options.Filters.Add(new AuthorizeFilter(policy)); }) .AddMicrosoftIdentityUI() .AddMvcLocalization() .AddViewLocalization() .AddDataAnnotationsLocalization(); builder.Services.AddSignalR(e => { e.EnableDetailedErrors = true; e.MaximumReceiveMessageSize = 102400000; }); }
问题现象
登出操作完成后,用户的Cookie/Token仍保持有效,可继续通过携带Cookie的请求访问需要身份验证的接口。复现步骤:
- 调用需用户身份的Ajax接口,将请求转为CURL命令
- 将CURL导入Postman等工具执行,请求仍能成功返回数据
示例CURL命令:
curl --location 'https://localhost:7114/XXX?handler=AllFiles&sessionId=75dd1c26-19c3-44c6-ad2f-b548a959e042&sessionLang=en-US&instance=dev&searchQuery=' \ --header 'accept: application/json, text/javascript, */*; q=0.01' \ --header 'accept-language: en-US,en;q=0.9' \ --header 'priority: u=1, i' \ --header 'referer: https://localhost:7114/XXX?instance=dev&culture=en-US&sessionId=75dd1c26-19c3-44c6-ad2f-b548a959e042' \ --header 'requestverificationtoken: CfDJ8GQXXXXXXXXXX.......' \ --header 'sec-ch-ua: "Google Chrome";v="141", "Not?A_Brand";v="8", "Chromium";v="141"' \ --header 'sec-ch-ua-mobile: ?0' \ --header 'sec-ch-ua-platform: "macOS"' \ --header 'sec-fetch-dest: empty' \ --header 'sec-fetch-mode: cors' \ --header 'sec-fetch-site: same-origin' \ --header 'Cookie: acknowledged-Terms of Use-1.0=true; .AspNetCore.Cookies=chunks-2; .AspNetCore.CookiesC1=CfDoYbp.........; .AspNetCore.CookiesC2=7LEbP2J.........'
已确认的行为
通过客户端网络日志和ASP.NET Core终端日志确认:
- Azure已发起远程登出调用
- 已成功触发
signout-callback-oidc请求,请求详情如下:
curl 'https://localhost:7114/signout-callback-oidc?state=CfDJ8GQMaRK5om......' \ -H 'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7' \ -H 'accept-language: en-US,en;q=0.9' \ -b 'acknowledged-Terms of Use-1.0=true' \ -H 'priority: u=0, i' \ -H 'referer: https://login.microsoftonline.com/' \ -H 'sec-ch-ua: "Google Chrome";v="141", "Not?A_Brand";v="8", "Chromium";v="141"' \ -H 'sec-ch-ua-mobile: ?0' \ -H 'sec-ch-ua-platform: "macOS"' \ -H 'sec-fetch-dest: document' \ -H 'sec-fetch-mode: navigate' \ -H 'sec-fetch-site: cross-site' \ -H 'upgrade-insecure-requests: 1' \ -H 'user-agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36'
预期结果
根据官方文档,登出后服务器应清除缓存中的Token,使Cookie失效,无法再通过携带Cookie的请求访问需要身份验证的接口。
内容的提问来源于stack exchange,提问作者Imran Sh
相关产品推荐
相关产品推荐

