DotNetOpenAuth.WebServerClient.XSRF-会话在回调期间发生变化

时间:2013-02-22 11:46:40

标签: asp.net .net oauth dotnetopenauth

我尝试设置简单的Oauth2登录身份验证。但是,我仍然停留在抛出以下异常的回调中:

   [ProtocolException: Unexpected OAuth authorization response received with callback and client state that does not match an expected value.]
   DotNetOpenAuth.Messaging.ErrorUtilities.VerifyProtocol(Boolean condition, String unformattedMessage, Object[] args) +426
   DotNetOpenAuth.OAuth2.WebServerClient.ProcessUserAuthorization(HttpRequestBase request) +771

here

讨论了完全相同的问题

在我的情况下,SessionID保持不变,但DotNetOpenAuth.WebServerClient.XSRF-Session cookie在回调时更改了它的值。

实现:

    public void Authorize(HttpRequest request)
    {
        string callbackString = request.Url.AbsoluteUri;
        Uri callbackUri = new Uri(callbackString);;

        IAuthorizationState authorization = nimbleClient.ProcessUserAuthorization();

        if (authorization == null)
        {
            // Kick off authorization request
            nimbleClient.RequestUserAuthorization(returnTo: callbackUri);
        }
        else
        {
            //Get AccesToken
            Uri.EscapeDataString(authorization.AccessToken);
        }

1 个答案:

答案 0 :(得分:0)

您是否已将Cookie声明为常量,如下所示:

private const string XsrfCookieName = "DotNetOpenAuth.WebServerClient.XSRF-Session"

这有助于在回调时保持价值。