【问题标题】:Session is not be destroyed when user sign out from ASP.net MVC application using Azure AD Authentication当用户使用 Azure AD 身份验证从 ASP.net MVC 应用程序注销时,会话不会被破坏
【发布时间】:2022-01-05 23:14:34
【问题描述】:

我正在开发 ASP.Net MVC 应用程序并使用 Azure AD 进行身份验证。我有一个问题,当我退出并重新登录时,我发现以前的会话仍然存在,并且在用户退出时它没有被杀死。

之前,我遇到了另一个问题,即每当用户退出并重新登录时,用户总是返回登录页面,除非关闭浏览器并重新登录。通过注释掉该问题已解决

app.UseCookieAuthentication(new CookieAuthenticationOptions());

并添加以下代码:

app.UseCookieAuthentication(new CookieAuthenticationOptions
 {
 AuthenticationType = "Cookies",
            CookieManager = new Microsoft.Owin.Host.SystemWeb.SystemWebChunkingCookieManager()
        });

这解决了无限返回登录页面,但后来我注意到会话没有被销毁。

有什么想法吗?

Code: 


startup:

    public void Configuration(IAppBuilder app)
     {
        
      app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

     


        //app.UseCookieAuthentication(new CookieAuthenticationOptions());

        app.UseCookieAuthentication(new CookieAuthenticationOptions
        {
            AuthenticationType = "Cookies",
            CookieManager = new Microsoft.Owin.Host.SystemWeb.SystemWebChunkingCookieManager()
        });


        app.UseOpenIdConnectAuthentication(
        new OpenIdConnectAuthenticationOptions
        {
            ClientId = clientId,
            Authority = authority,
            RedirectUri = redirectUri,
            // PostLogoutRedirectUri is the page that users will be redirected to after sign-out. In this case, it is using the home page
            PostLogoutRedirectUri = redirectUri,
            Scope = OpenIdConnectScope.OpenIdProfile,

            // ResponseType is set to request the code id_token - which contains basic information about the signed-in user
            ResponseType = OpenIdConnectResponseType.CodeIdToken,
            
            //ResponseType = OpenIdConnectResponseType.IdToken,
            // OpenIdConnectAuthenticationNotifications configures OWIN to send notification of failed authentications to OnAuthenticationFailed method
            Notifications = new OpenIdConnectAuthenticationNotifications
            {
                AuthenticationFailed = OnAuthenticationFailed,
                //AuthorizationCodeReceived = OnAuthorizationCodeReceivedAsync,
                //SecurityTokenValidated = OnSecurityTokenValidatedAsync

            }
        }
    );
    }

具有登录和注销逻辑的主页。

 public async Task<ActionResult> Index()
    {
        if (Request.IsAuthenticated)
        {
            var userName = 
             System.Security.Claims.ClaimsPrincipal.Current.FindFirst("name").Value;
         
            return RedirectToAction("Summary", "DashBoard");
            
         }
        return View();
    }
    /// <summary>
    /// Send an OpenID Connect sign-in request.
    /// Alternatively, you can just decorate the SignIn method with the [Authorize] attribute
    /// </summary>
    public void SignIn()
    {
       

        try
        {
            if (!Request.IsAuthenticated)
            {
                HttpContext.GetOwinContext().Authentication.Challenge(
                    new AuthenticationProperties { RedirectUri = "/" },
                    OpenIdConnectAuthenticationDefaults.AuthenticationType);
            }
        }
        catch(Exception ex)
        {
            Log.Error(ex.Message);
            throw;

        }
    }

    /// <summary>
    /// Send an OpenID Connect sign-out request.
    /// </summary>
    public void SignOut()
    {           
                  HttpContext.GetOwinContext().Authentication.SignOut(
            OpenIdConnectAuthenticationDefaults.AuthenticationType,
            CookieAuthenticationDefaults.AuthenticationType);       


    }
}

【问题讨论】:

    标签: authentication azure-active-directory msal


    【解决方案1】:

    在解决方法上尝试以下解决方案

    解决方案 1) 在 ASP.NET 中,您委托中间件执行注销,清除会话 cookie:

     public void EndSession()
     {
      Request.GetOwinContext().Authentication.SignOut();
      Request.GetOwinContext().Authentication.SignOut(Microsoft.AspNet.Identity.DefaultAuthenticationTypes.ApplicationCookie);
      this.HttpContext.GetOwinContext().Authentication.SignOut(CookieAuthenticationDefaults.AuthenticationType);
     }
    

    解决方案 2) 尝试Response.redirect

    public void SignOut()
    {
     HttpContext.GetOwinContext()
                .Authentication
                .SignOut(CookieAuthenticationDefaults.AuthenticationType);
     Response.Redirect("/");
    }
    

    更多详情请参考document:

    解决方案 3) 使用Current

    HttpContext.Current.GetOwinContext().Authentication.SignOut(
                CookieAuthenticationDefaults.AuthenticationType, 
                OpenIdConnectAuthenticationDefaults.AuthenticationType);
    

    更多详情请参考SO Thread:

    【讨论】:

      猜你喜欢
      • 2012-08-22
      • 2018-07-31
      • 2021-10-04
      • 1970-01-01
      • 2022-10-25
      • 1970-01-01
      • 1970-01-01
      • 2017-05-02
      • 2010-12-16
      相关资源
      最近更新 更多