.NET 4.7.2下ASP.NET MVC嵌入IFrame防伪Cookie缺失问题排查
自昨日起,运行在.NET 4.7.2上、嵌入到IFrame中的ASP.NET MVC Web应用停止工作,报错信息如下:
所需的防伪Cookie "__RequestVerificationToken"不存在。
测试代码
为排查问题编写的测试页面代码:
<!DOCTYPE html> <html> <head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1" /> <title>Testing IFrame</title> </head> <body> Página de teste da IFrame <br> <iframe width="100%" height="600px" src="https://www.website.com/"></iframe> </body> </html>
站点中的Ajax表单
website.com站点内的Ajax表单代码:
@using (Ajax.BeginForm(MVC.Home.Search(), new AjaxOptions { UpdateTargetId = "idx-list-ctn", InsertionMode = InsertionMode.Replace, OnBegin = "SearchForm.onBegin()", OnSuccess = "SearchForm.onSuccess()" }, new { @id = "sch-frm" })) { @Html.AntiForgeryToken(); }
控制器方法
表单提交对应的控制器方法:
[HttpPost, ValidateAntiForgeryToken] public virtual async Task<PartialViewResult> Search(PartnerSearchVM searchVM) { }
已尝试的配置
1. Global.asax强制设置Cookie属性
尝试在Application_EndRequest中强制配置__RequestVerificationToken的SameSite为None,但未解决问题:
protected void Application_EndRequest() { // Ajusta SameSite e Secure do cookie de antiforgery var antiForgeryCookie = Response.Cookies["__RequestVerificationToken"]; if (antiForgeryCookie != null) { antiForgeryCookie.Secure = true; // HTTPS obrigatório antiForgeryCookie.SameSite = (System.Web.SameSiteMode)(-1); // Forçar None antiForgeryCookie.HttpOnly = true; } }
2. web.config配置IFrame规则
已在web.config中添加Content-Security-Policy允许指定父站点嵌入:
<httpProtocol> <customHeaders> <add name="Content-Security-Policy" value="frame-ancestors 'self' https://parent-website.com;" /> </customHeaders> </httpProtocol>
现寻求该问题的有效解决办法。
内容的提问来源于stack exchange,提问作者Patrick
相关产品推荐
相关产品推荐

