为什么AllowAnonymous在部署到Azure网站时不起作用?

Jon*_*ski 7 asp.net-mvc authorization asp.net-mvc-4

我有一个带有以下控制器的MVC4 Web应用程序

[Authorize]
public class AccountController : BaseController
{
  [AllowAnonymous]
  public ActionResult SignInRegister(LoginModel loginModel, string returnUrl)
  {
    //some implementation
  }
  //other secured actions
}
Run Code Online (Sandbox Code Playgroud)

这在本地运行时按预期工作,但是一旦我将其部署到Free Azure网站,我会收到一条401错误代码,其中包含以下消息:You do not have permission to view this directory or page.

删除[Authorize]属性并重新部署按预期工作,再次添加并重新部署会带来问题.

我甚至尝试了完全限定的类名:System.Web.Mvc.Authorize并且System.Web.Mvc.AllowAnonymous结果相同.

该应用程序使用的是.NET 4.5,Azure网站也配置为使用4.5.

更新: 该BaseController具有返回报头,为未经装饰的局部视图的动作[AllowAnonymous].在本地,它导致页面显示没有标题,但在Azure网站上,响应被切断,只返回上面提到的错误消息.在我故意调查它之前,我没有意识到标题丢失了.

现在问题有待提出:为什么Azure网站会覆盖响应?

Jon*_*ski 4

BaseController 有一个操作,该操作将 Header 作为未用 [AllowAnonymous] 修饰的部分视图返回。在本地,它导致页面显示时没有标题,但在 Azure 网站上,响应被切断,仅返回上述错误消息。在我特意查看之前,我没有意识到标头丢失了。

现在要问的问题是:为什么 Azure 网站会覆盖响应?