【问题标题】:How to properly remove .AspNet.TwoFactorRememberBrowser cookie after disabling user's 2FA?禁用用户的 2FA 后如何正确删除 .AspNet.TwoFactorRememberBrowser cookie?
【发布时间】:2019-01-07 20:14:43
【问题描述】:

Microsoft.AspNet.Identity V2.2: 当用户禁用 2FA(之前已启用)用户的 cookie .AspNet.TwoFactorRememberBrowser 仍然存在,并且在适当的情况下可能会带来安全风险。我正在寻找一种干净且适当的方法来删除该用户的 cookie,或者我应该只是将过期日期更改为过去的日期 - 如果是这样,我将如何做到这一点?我用谷歌搜索了一堆都无济于事,好像没有人意识到 cookie 仍然存在。

【问题讨论】:

    标签: asp.net .net asp.net-mvc asp.net-identity


    【解决方案1】:

    因此,在没有更好的方法的情况下,看起来这可以解决异步函数 /Manage/DisableTwoFactorAuthentication 的问题。请注意,isPersistent = True 会删除 cookie,而 isPersistent = False 只是将过期日期设置回来。

    ' POST: /Manage/DisableTwoFactorAuthentication
    <HttpPost>
    <ValidateAntiForgeryToken>
    Public Async Function DisableTwoFactorAuthentication() As Task(Of ActionResult)
        Await UserManager.SetTwoFactorEnabledAsync(User.Identity.GetUserId(), False)
        Dim userInfo = Await UserManager.FindByIdAsync(User.Identity.GetUserId())
        If userInfo IsNot Nothing Then
            Await SignInManager.SignInAsync(userInfo, isPersistent:=False, rememberBrowser:=False)
            Dim rememberBrowserIdentity = AuthenticationManager.CreateTwoFactorRememberBrowserIdentity(userInfo.Id)
            AuthenticationManager.SignIn(New AuthenticationProperties With {
                .IsPersistent = True,   'False still leaves old cookie but with expired date
                .ExpiresUtc = Date.UtcNow.AddDays(-1)
            }, rememberBrowserIdentity)
        End If
        Return RedirectToAction("Index", "Manage")
    End Function
    

    希望这对某人有所帮助! :-)

    【讨论】:

      猜你喜欢
      • 2020-04-08
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2021-01-17
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2019-05-04
      相关资源
      最近更新 更多