【问题标题】:Net Core 2.1 Bearer was not authenticated error in ControllerNet Core 2.1 Bearer 在控制器中未通过身份验证错误
【发布时间】:2019-03-22 16:12:50
【问题描述】:

我在 net core 2.1 中遇到错误:

承载未通过身份验证。

失败消息:没有可用于令牌的 SecurityTokenValidator:null

asp net 输出窗口为:

info: Microsoft.AspNetCore.Authentication.JwtBearer.JwtBearerHandler[7]
Bearer was not authenticated. Failure message: No SecurityTokenValidator available for token: null
info: Microsoft.AspNetCore.Cors.Infrastructure.CorsService[4]
Policy execution successful.

帐户控制器代码在这里:

namespace quiz_backend.Controllers
{
    public class Credentials
    {
        public string Email { get; set; }
        public string Password { get; set; }
    }

    [Produces("application/json")]
    [Route("api/Account")]
    public class AccountController : Controller
    {
        readonly UserManager<IdentityUser> userManager;
        readonly SignInManager<IdentityUser> signInManager;

        public AccountController(UserManager<IdentityUser> userManager, SignInManager<IdentityUser> signInManager)
        {
            this.userManager = userManager;
            this.signInManager = signInManager;
        }

        [HttpPost]
        public async Task<IActionResult> Register([FromBody] Credentials credentials)
        {
            var user = new IdentityUser { 
                UserName = credentials.Email, 
                Email = credentials.Email 
            };

            var result = await userManager.CreateAsync(user, credentials.Password);

            if (!result.Succeeded)
                return BadRequest(result.Errors);

            await signInManager.SignInAsync(user, isPersistent: false);
            // create a token
            var signingKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes("this is the secret phrase"));
            var signingCredentials = new SigningCredentials(signingKey, SecurityAlgorithms.HmacSha256);
            var jwt = new JwtSecurityToken(signingCredentials: signingCredentials);
            return Ok(new JwtSecurityTokenHandler().WriteToken(jwt));
        }
    }
}

这里是 startup.cs

namespace quiz_backend
{
    public class Startup
    {
        public Startup(IConfiguration configuration)
        {
            Configuration = configuration;
        }

        public IConfiguration Configuration { get; }

        // This method gets called by the runtime. Use this method to add services to the container.
        public void ConfigureServices(IServiceCollection services)
        {
            services.AddCors(options => options.AddPolicy("Cors", builder =>
            {
                builder.AllowAnyOrigin()
                .AllowAnyMethod()
                .AllowAnyHeader();
            }));

            services.AddDbContext<QuizContext>(opt =>opt.UseInMemoryDatabase("quiz"));
            services.AddDbContext<UserDbContext>(opt => opt.UseInMemoryDatabase("user"));

            services.AddIdentity<IdentityUser, IdentityRole>().AddEntityFrameworkStores<UserDbContext>();
            var signingKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes("this is the secret phrase"));
            services.AddAuthentication(options =>{
                options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
                options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
            }).AddJwtBearer(cfg => {
                cfg.RequireHttpsMetadata = false;
                cfg.SaveToken = true;
                cfg.TokenValidationParameters = new TokenValidationParameters()
                {
                    IssuerSigningKey = signingKey,
                    ValidateAudience = false,
                    ValidateLifetime = false,
                    ValidateIssuerSigningKey = true
                };
            });
            services.AddMvc();
        }

        // This method gets called by the runtime. Use this method to configure the HTTP request pipeline.
        public void Configure(IApplicationBuilder app, IHostingEnvironment env)
        {
            app.UseAuthentication();
            if (env.IsDevelopment())
            {
                app.UseDeveloperExceptionPage();
            }

            app.UseCors("Cors");
            
            app.UseMvc();
        }
    }
}

这是将令牌附加到 ts 中的标头的前端验证代码:

export class AuthInterceptor implements HttpInterceptor {
    constructor() {}
    intercept(req, next) {
        var token = localStorage.getItem('token')
        var authRequest = req.clone({
            headers: req.headers.set('Authorization', `Bearer ${token}`)
        })
        return next.handle(authRequest)
    }
}

【问题讨论】:

  • 无法使用您的代码重现相同的错误。您能否澄清一下在哪种情况下会发生错误?
  • 非常感谢您检查我的代码。当我注册一个有角度的前端用户时会发生这种情况。我确实收到了令牌。我应该查看我的 angular ts 代码以获取帐户
  • 谢谢 itminus,我不知道为什么,但它今天有效。我使用您的评论没有更改 CORE 2.1 中的任何内容。我查看了我的角度代码,没有发现任何问题。我正在单步执行我的代码,调试,它成功了!我很感激你的时间。

标签: c# asp.net-core jwt bearer-token


【解决方案1】:

根据您的代码,问题似乎是收到的令牌无效(NULL)。

失败消息:没有可用于令牌的 SecurityTokenValidator:null

首先,您应该确保令牌按预期到达。

【讨论】:

    猜你喜欢
    • 1970-01-01
    • 2019-04-19
    • 2021-05-15
    • 2017-07-24
    • 2015-11-04
    • 1970-01-01
    • 2018-12-07
    • 1970-01-01
    • 2020-07-23
    相关资源
    最近更新 更多