【发布时间】:2021-06-30 12:36:17
【问题描述】:
我有一个简单的 JWT 身份验证示例,您可以找到它here
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddJwtBearer(options =>
如您所见,我已将JwtBearerDefaults.AuthenticationScheme 添加到Startup/ConfigureServices 方法内的Authentication,因此我应该能够使用[Authorize] 独立,如下所示
[Authorize]
public sealed class WeatherForecastController : BaseController
{
private static readonly string[] Summaries = new[]
{
"Freezing", "Bracing", "Chilly", "Cool", "Mild", "Warm", "Balmy", "Hot", "Sweltering", "Scorching"
};
但我不知道为什么它不起作用! (我已经用 Postman 测试过)。我必须通过AuthenticationSchemes定义它。
[Authorize(AuthenticationSchemes = JwtBearerDefaults.AuthenticationScheme)]
public sealed class WeatherForecastController : BaseController
{
private static readonly string[] Summaries = new[]
{
"Freezing", "Bracing", "Chilly", "Cool", "Mild", "Warm", "Balmy", "Hot", "Sweltering", "Scorching"
};
谁能指导我如何使用Authorize 独立属性没有 AuthenticationSchemes,尤其是当我在ConfigureServices 中定义它时?我设置错了什么?
【问题讨论】:
-
我认为你应该 1:ConfigureServices 方法中的 services.AddAuthorization(),而不是 2:Configure 方法中的 app.UseAuthorization(),以便使用 ASP.Net 的授权功能,之后您应该在不指定方案的情况下获得授权
标签: c# asp.net-core jwt asp.net-identity