如何在Blazor Server Side(Razor组件)中实现身份验证。我正在使用.net 3预览5。我当前正在使用AspNetCore.Identity。注册用户可以正常工作,但是调用任何SignIn方法都会导致异常(响应已启动)。
这里有一些代码-它是唯一的玩具/原型,所以有点混乱。一旦我向自己证明了使用Identity和Blazor Server Side的实际可能性,将进行重写!
@page "/signup"
@using System.Security.Claims
@using AuthProto.Data
@using AuthProto.Entities
@using Microsoft.AspNetCore.Authentication
@using Microsoft.AspNetCore.Authentication.Cookies
@using Microsoft.AspNetCore.Http
@using Microsoft.AspNetCore.Http.Extensions
@using Microsoft.AspNetCore.Identity
@using Microsoft.AspNetCore.Identity.EntityFrameworkCore
@inject WeatherForecastService ForecastService
@inject SignInManager<AppUser> SignInManager
@inject UserManager<AppUser> UserManager
@inject UserDb db;
<h1>Signup</h1>
<h2>@message</h2>
<EditForm Model="@data" OnValidSubmit="@HandleValidSubmit">
<DataAnnotationsValidator />
<ValidationSummary />
<InputText id="name" bind-Value="@data.Email" />
<InputText id="password" bind-Value="@data.Password" />
<button type="submit">Submit</button>
</EditForm>
<h2>Login</h2>
<EditForm Model="@login" OnValidSubmit="@HandleLogin">
<DataAnnotationsValidator />
<ValidationSummary />
<InputText id="name" bind-Value="@login.email" />
<InputText id="password" bind-Value="@login.password" />
<button type="submit">Submit</button>
</EditForm>
@functions {
private SignupApi data = new SignupApi();
private LoginApi login = new LoginApi();
private string message;
WeatherForecast[] forecasts;
protected override async Task OnInitAsync()
{
forecasts = await ForecastService.GetForecastAsync(DateTime.Now);
}
private void HandleValidSubmit()
{
var user = new AppUser() { Email = data.Email, UserName = data.Email };
IdentityResult result = UserManager.CreateAsync(user, data.Password).Result;
if (result.Succeeded)
{
message = string.Format("User {0} was created successfully!", user.UserName);
// var signInResult = SignInManager.PasswordSignInAsync(
// user, data.Password, false, false).Result;
}
else
{
message = result.Errors.FirstOrDefault()?.Description;
}
}
private async void HandleLogin()
{
var x = db.Users.SingleOrDefault(u => u.Email == data.Email);
var result = SignInManager.CheckPasswordSignInAsync(x, data.Password, true).Result;
await SignInManager.SignInAsync(x, true);
}
}
我也尝试过使用HttpAssessor手动访问HttpContext.SigninAsync-没有例外,但没有设置cookie。
我猜测问题是Identity目前无法与Blazor Server Side和SignIn方法兼容,因此类似的方法是启动响应,然后在调用后添加到响应中。我认为这会导致SignalR与客户端的通讯出现问题。
答案 0 :(得分:1)
身份包含在Blazor项目模型中,因此我认为这是进行身份验证的好方法。因此,您仍然需要C#类SignInManager提供身份验证行为(必须在Startup.cs文件中的ConfigureService方法中进行设置) 由于它继承自SignInManager接口,因此具有与HttpContext相对应的Context属性。它可用于携带ClaimsPrincipal和cookie详细信息。不过对于Cookie,您需要在Startup.cs中添加优质服务:
service.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
.AddCookie(CookieAuthenticationDefaults.AuthenticationScheme);
Startup.cs exemple 我用它来创建一个新的应用程序,该数据库不用于身份验证,并且可以正常工作。