OWIN OpenID提供程序 - GetExternalLoginInfo()返回null

Mar*_*cus 5 c# openid owin asp.net-mvc-5 asp.net-identity

我在使用ASP.NET身份的ASP.NET MVC5应用程序中遇到OWIN OpenId提供程序的问题,并且基于具有个人用户帐户身份验证的VS2013模板.用于Google和LinkedIn的OWIN OpenID提供程序用于登录身份验证.

问题是看起来很随机; 即使登录验证成功,GetExternalLoginInfo()也会在LoginConfirmation回调中返回null.

var authManager = HttpContext.Current.GetOwinContext().Authentication;
var login = authManager.GetExternalLoginInfo();
Run Code Online (Sandbox Code Playgroud)

使用的提供商是Google(Microsoft.Owin.Security.Google 2.1.0)和LinkedIn(来自Owin.Security.Providers 1.3),两家提供商都会导致同样的问题.

有时它失败一次然后再次工作,但有时它会继续失败,直到AppPool被回收.

目前,应用程序的两个实例托管在同一Windows Azure虚拟机上的IIS中.每个实例都有自己的AppPool但设置相同(不同的子域).有时登录停止在一个实例上工作,但仍然在另一个实例上工作.

这个问题也在本地重现(IIS Express - VS2013).

任何人都遇到类似的OWIN OpenID身份验证问题?

Startup.Auth.cs看起来像这样:

public void ConfigureAuth(IAppBuilder app)
{
    // Enable the application to use a cookie to store information for the signed in user
    app.UseCookieAuthentication(new CookieAuthenticationOptions
    {
        AuthenticationType = DefaultAuthenticationTypes.ApplicationCookie,
        LoginPath = new PathString("/Account/Login"),
    });
    // Use a cookie to temporarily store information about a user logging in with a third       party login provider
    app.UseExternalSignInCookie(DefaultAuthenticationTypes.ExternalCookie);

    app.UseGoogleAuthentication();

    app.UseLinkedInAuthentication("clientId", "clientSecret");
}
Run Code Online (Sandbox Code Playgroud)

以下OWIN nuget包正在使用中:

  <package id="Microsoft.AspNet.Identity.Core" version="1.0.0" targetFramework="net45" />
  <package id="Microsoft.AspNet.Identity.Owin" version="1.0.0" targetFramework="net45" />
  <package id="Microsoft.Owin" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Host.SystemWeb" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.ActiveDirectory" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.Cookies" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.Facebook" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.Google" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.Jwt" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.MicrosoftAccount" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.OAuth" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Owin.Security.Twitter" version="2.1.0" targetFramework="net45" />
  <package id="Microsoft.Web.Infrastructure" version="1.0.0.0" targetFramework="net45" />
  <package id="Owin" version="1.0" targetFramework="net45" />
  <package id="Owin.Security.Providers" version="1.3" targetFramework="net45" />
  <package id="System.IdentityModel.Tokens.Jwt" version="3.0.2" targetFramework="net45" />
Run Code Online (Sandbox Code Playgroud)

Mar*_*cus 16

当ASP.NET_SessionIdcookie丢失时会出现问题.

在重定向到OpenID提供程序以获取凭据之前在会话中设置虚拟值似乎可以解决问题:

[AllowAnonymous]
public ActionResult Login(string returnUrl)
{
    Session["dummy"] = "dummy"; // Create ASP.NET_SessionId cookie

    return View();
}
Run Code Online (Sandbox Code Playgroud)

本答案中的更多详细信息:https://stackoverflow.com/a/21234614/205023