【问题标题】:Web api 302 status redirectWeb api 302 状态重定向
【发布时间】:2015-05-14 14:04:13
【问题描述】:

我有一个包含 AngularJS、WebApi2 和 FormAuthentication 的项目。 因为我需要从使用 session 来存储一些用户变量的 WebForms 项目中导入一些旧代码,所以我必须在 WebApi 中实现 Session。

在 WebConfig 我有:

`

 <authentication mode="Forms">
      <forms loginUrl="/index.html" defaultUrl="/Areas/Modeler/modeler.html" name=".ASPXFORMSAUTH" protection="All" cookieless="UseDeviceProfile" slidingExpiration="true" path="/" domain="" requireSSL="false" timeout="600" enableCrossAppRedirects="false">
      </forms>
</authentication>
<authorization>
        <allow users="*" />
</authorization>
<machineKey validationKey="xxxxx" decryptionKey="xxxxxx" validation="SHA1" />
</system.web>
<location path="Scripts">
    <system.web>
        <authorization>
            <allow users="*" />
        </authorization>
    </system.web>
</location>
<location path="~/Authenticate">
    <system.web>
        <authorization>
            <allow users="*" />
        </authorization>
    </system.web>
</location>

`

我在 Global.asax.cs 中进行了以下更改以实现 Session:

`

public override void Init()
        {
            this.PostAuthenticateRequest += Application_PostAuthorizeRequest;
            base.Init();
        }
protected void Application_Start()
        {
            AreaRegistration.RegisterAllAreas();
            GlobalConfiguration.Configure(WebApiConfig.Register);
            GlobalConfiguration.Configuration.IncludeErrorDetailPolicy = IncludeErrorDetailPolicy.Always;
        }
protected void Application_PostAuthorizeRequest(object sender, EventArgs e)
        {
            var url = HttpContext.Current.Request.AppRelativeCurrentExecutionFilePath;
            var auth = Context.Request.IsAuthenticated;
            HttpContext.Current.SetSessionStateBehavior(SessionStateBehavior.Required);
        }`

用户输入姓名和密码后,我调用一个post方法~/Authenticate/Login。

在 chrome 浏览器网络选项卡中,我可以看到下两行: 登录方式:POST,状态 302 登录方法 GET,状态 405 第一次通话:

Remote Address:[::1]:52966 Request URL:http://localhost:52966/Authenticate/Login Request Method:POST Status Code:302 Found Response Headers view source Content-Length:166 Date:Thu, 14 May 2015 13:11:24 GMT Location:/(S(tdd41h23pms5lllzyro1hltq))/Authenticate/Login Server:Microsoft-IIS/8.0 X-Powered-By:ASP.NET X-SourceFiles:=?UTF-8?B?RDpcUHJvamVjdH..............=?= Request Headers view source Accept:application/json, text/plain, */* Accept-Encoding:gzip, deflate Accept-Language:en-US,en;q=0.8,ro;q=0.6 Connection:keep-alive Content-Length:44 Content-Type:application/json;charset=UTF-8 Cookie:PHPSESSID=d5djbkgs7ttui073jl04mg6st3; __AntiXsrfToken=97b6e321343944a89ade4acc098305bd; ASP.NET_SessionId=2ggakcj1qxtewgsrh5qvtw40; _session_id=BAh7B0kiD3Nlc3Npb25faW....; .AspNet.ApplicationCookie=GcQUqnFHbPaX...; UserPassword=password; UserName=admin; .ASPXFORMSAUTH=7B15EE3DE... DNT:1 Host:localhost:52966 Origin:http://localhost:52966 Referer:http://localhost:52966/index.html User-Agent:Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Request Payload view source {userName: "admin", userPassword: "password"}

问题是:为什么对 Login 的调用会被重定向? 在 Global.ascx.cs ai 的 Application_PostAuthorizeRequest 方法中检查 Context.Request.IsAuthenticated 是否为真。

【问题讨论】:

    标签: asp.net-web-api http-status-code-302 form-authentication


    【解决方案1】:

    重定向来自配置。您已经配置了 loginUrl 和 defaultUrl。这是在身份验证之前和之后分别发送用户的位置。

    【讨论】:

    • 如果我不更改使用Webapi中的会话,则问题不存在。这就是在 web.config 中配置 Form Authentication 的方式。
    • 您的问题是“为什么对登录的调用被重定向?”。我的回答是因为您将“index.html”配置为登录页面。因此,当您尝试访问 /Authenticate/login 时,如果您尚未通过身份验证,您将被重定向到“index.html”。这可能是与会话问题不同的问题。
    • 好的。那么为什么当我不使用会话时不会以同样的方式发生呢?在这种情况下,它使用状态码 200 执行的 web api 方法。
    • 并且方法 Login 使用属性 [AllowAnonymous] 进行了描述,在 web.config 中我有:
    • 我认为,访问webapi方法登录是不需要认证的
    猜你喜欢
    • 2017-10-20
    • 2018-03-30
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2013-09-04
    • 2022-01-05
    • 1970-01-01
    • 2017-03-16
    相关资源
    最近更新 更多