【发布时间】:2020-05-10 11:35:02
【问题描述】:
我正在使用令牌验证中间件对用户进行身份验证,为此它会访问另一台服务器。但问题是,即使不需要,它也会始终检查令牌,即在使用注册 API 或任何其他不需要任何验证的时候。
这是我的 TokenValidationMiddleware.cs 文件。
public async Task Invoke(HttpContext httpContext, UserManager<ApplicationUser> userManager)
{
_userManager = userManager;
// **>>>>>BELOW CHECK IS MANUAL, WHICH IS ALSO NOT CORRECT.<<<<<**
if (!httpContext.Request.Path.StartsWithSegments("/api/Authentication/Login") && !httpContext.Request.Path.StartsWithSegments("/api/Authentication/Refresh"))
{
var headerKeys = httpContext.Request.Headers.Keys;
// **issue comes here**
// **it always discard the request which does not have any token.**
if (headerKeys.Contains("Authorization"))
{
// validation code, which hits another server.
}
else
{
httpContext.Response.StatusCode = (int)HttpStatusCode.Unauthorized;
await httpContext.Response.WriteAsync("Unauthorized Access");
return;
}
}
await _next.Invoke(httpContext);
}
此中间件始终检查所提出的每个请求的令牌验证。
对于匿名请求,或者在控制器或特定端点上没有任何 [Authorize] 属性的请求,我想绕过这个中间件。
一种解决方案是将所有匿名端点存储在某个地方并检查中间件,这根本不正确。
其他是将所有安全端点的路由修改为“api/secure/[controller]”,但为此我必须修改后端和前端中的所有端点。这也不是一个好方法。
请为此提出解决方案。
提前致谢。
【问题讨论】:
标签: c# asp.net-core-webapi identityserver4 access-token asp.net-core-middleware