Blazer服务器端+ AspNetCore.Identity

时间:2019-05-19 12:27:26

标签: blazor blazor-server-side

如何在Blazor Server Side(Razor组件)中实现身份验证。我正在使用.net 3预览5。我当前正在使用AspNetCore.Identity。注册用户可以正常工作,但是调用任何SignIn方法都会导致异常(响应已启动)。

这里有一些代码-它是唯一的玩具/原型,所以有点混乱。一旦我向自己证明了使用Identity和Blazor Server Side的实际可能性,将进行重写!

@page "/signup"
@using System.Security.Claims
@using AuthProto.Data
@using AuthProto.Entities
@using Microsoft.AspNetCore.Authentication
@using Microsoft.AspNetCore.Authentication.Cookies
@using Microsoft.AspNetCore.Http
@using Microsoft.AspNetCore.Http.Extensions
@using Microsoft.AspNetCore.Identity
@using Microsoft.AspNetCore.Identity.EntityFrameworkCore
@inject WeatherForecastService ForecastService
@inject SignInManager<AppUser> SignInManager
@inject UserManager<AppUser> UserManager
@inject UserDb db;
<h1>Signup</h1>

<h2>@message</h2>
<EditForm Model="@data" OnValidSubmit="@HandleValidSubmit">
    <DataAnnotationsValidator />
    <ValidationSummary />

    <InputText id="name" bind-Value="@data.Email" />
    <InputText id="password" bind-Value="@data.Password" />

    <button type="submit">Submit</button>
</EditForm>
<h2>Login</h2>
<EditForm Model="@login" OnValidSubmit="@HandleLogin">
    <DataAnnotationsValidator />
    <ValidationSummary />

    <InputText id="name" bind-Value="@login.email" />
    <InputText id="password" bind-Value="@login.password" />

    <button type="submit">Submit</button>
</EditForm>

@functions {

    private SignupApi data = new SignupApi();
    private LoginApi login = new LoginApi();
    private string message;

    WeatherForecast[] forecasts;

    protected override async Task OnInitAsync()
    {
        forecasts = await ForecastService.GetForecastAsync(DateTime.Now);
    }

    private void HandleValidSubmit()
    {
        var user = new AppUser() { Email = data.Email, UserName = data.Email };
        IdentityResult result = UserManager.CreateAsync(user, data.Password).Result;

        if (result.Succeeded)
        {
            message = string.Format("User {0} was created successfully!", user.UserName);

            //   var signInResult = SignInManager.PasswordSignInAsync(
            //     user, data.Password, false, false).Result;
        }
        else
        {
            message = result.Errors.FirstOrDefault()?.Description;
        }
    }

    private async void HandleLogin()
    {
        var x = db.Users.SingleOrDefault(u => u.Email == data.Email);

        var result = SignInManager.CheckPasswordSignInAsync(x, data.Password, true).Result;
        await SignInManager.SignInAsync(x, true);
    }
}

我也尝试过使用HttpAssessor手动访问HttpContext.SigninAsync-没有例外,但没有设置cookie。

我猜测问题是Identity目前无法与Blazor Server Side和SignIn方法兼容,因此类似的方法是启动响应,然后在调用后添加到响应中。我认为这会导致SignalR与客户端的通讯出现问题。

1 个答案:

答案 0 :(得分:1)

身份包含在Blazor项目模型中,因此我认为这是进行身份验证的好方法。因此,您仍然需要C#类SignInManager提供身份验证行为(必须在Startup.cs文件中的ConfigureService方法中进行设置) 由于它继承自SignInManager接口,因此具有与HttpContext相对应的Context属性。它可用于携带ClaimsPrincipal和cookie详细信息。不过对于Cookie,您需要在Startup.cs中添加优质服务:

service.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
.AddCookie(CookieAuthenticationDefaults.AuthenticationScheme);

Startup.cs exemple 我用它来创建一个新的应用程序,该数据库不用于身份验证,并且可以正常工作。