Configure Auth

dotnet/skills/plugins/dotnet-blazor/skills/configure-auth

作者 dotnet0608d8924cd3MIT5.5K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Add authentication and authorization to a Blazor Web App, accounting for the app's render mode. USE WHEN the user needs [Authorize] on pages, AuthorizeView, role or policy-based access, login/logout Identity pages, or AuthenticationStateProvider. Also USE WHEN auth state is null after WebAssembly loads, SignInManager throws in an interactive component, NotAuthorized content never renders in static SSR, or HttpContext.User is null in an interactive component. DO NOT USE for general component authoring (see author-component), for prerendering concerns unrelated to auth (see support-prerendering), or for managing non-auth cascading state (see coordinate-components).

AI 生成的概览

指导为 Blazor Web App 添加身份验证和授权,并考虑应用的呈现模式。

功能
该技能提供分步说明,用于将身份验证和授权接入 Blazor Web App。内容涵盖在 Program.cs 中注册身份验证服务、使用 AuthorizeRouteView 配置 App.razor 和 Routes.razor、通过 [Authorize] 和 AuthorizeView 保护页面、让 Identity 页面保持静态 SSR,以及为 WebAssembly 或 Auto 模式序列化身份验证状态。它还包含呈现模式与身份验证的对照表,以及常见错误、症状和修复方法表。
适用场景
当 Blazor 应用需要在页面上使用 [Authorize]、AuthorizeView、基于角色或策略的访问、登录/注销 Identity 页面或 AuthenticationStateProvider 时使用。它也适用于 WebAssembly 加载后身份验证状态为 null、SignInManager 在交互式组件中抛出异常、NotAuthorized 内容在静态 SSR 中始终不呈现,或交互式组件中 HttpContext.User 为 null 的情况。
运行要求
不附带脚本,仅为说明性内容。它假定存在 Blazor Web App 项目,并在相关场景中使用 ASP.NET Core Identity 和 Entity Framework Core;代理在做出更改前应阅读工作区根目录下的 AGENTS.md。

Configure Auth

Step 1 — Read AGENTS.md

Read AGENTS.md at the workspace root for the project's interactivity mode and scope before making changes.

Step 2 — Register auth services in Program.cs

csharp
// Program.cs (server project)builder.Services.AddCascadingAuthenticationState();builder.Services.AddAuthorization();

For ASP.NET Core Identity add the Identity services:

csharp
builder.Services.AddAuthentication(options =>{    options.DefaultScheme = IdentityConstants.ApplicationScheme;    options.DefaultSignInScheme = IdentityConstants.ExternalScheme;}).AddIdentityCookies();
builder.Services.AddIdentityCore<ApplicationUser>()    .AddRoles<IdentityRole>()    .AddEntityFrameworkStores<ApplicationDbContext>()    .AddSignInManager()    .AddDefaultTokenProviders();

Step 3 — Wire App.razor for auth and render mode

The App.razor component must use AuthorizeRouteView and conditionally apply the render mode so that pages excluded from interactive routing render statically.

razor
<!DOCTYPE html><html><head>    <HeadOutlet @rendermode="RenderModeForPage" /></head><body>    <Routes @rendermode="RenderModeForPage" />    <script src="_framework/blazor.web.js"></script></body></html>
@code {    [CascadingParameter]    public HttpContext HttpContext { get; set; } = default!;
    private IComponentRenderMode? RenderModeForPage =>        HttpContext.AcceptsInteractiveRouting()            ? InteractiveServer   // replace with the app's render mode            : null;}

In Routes.razor (or wherever the router lives), use AuthorizeRouteView:

razor
<Router AppAssembly="typeof(Program).Assembly">    <Found Context="routeData">        <AuthorizeRouteView RouteData="routeData"                            DefaultLayout="typeof(Layout.MainLayout)">            <NotAuthorized>                @if (context.User.Identity?.IsAuthenticated != true)                {                    <RedirectToLogin />                }                else                {                    <p>You are not authorized to access this resource.</p>                }            </NotAuthorized>        </AuthorizeRouteView>        <FocusOnNavigate RouteData="routeData" Selector="h1" />    </Found></Router>

Step 4 — Protect pages and components

[Authorize] attribute on pages

razor
@page "/admin"@attribute [Authorize]

With roles or policies:

razor
@attribute [Authorize(Roles = "Admin")]@attribute [Authorize(Policy = "RequireManager")]

AuthorizeView for conditional UI

razor
<AuthorizeView>    <Authorized>Welcome, @context.User.Identity?.Name!</Authorized>    <NotAuthorized><a href="Account/Login">Log in</a></NotAuthorized></AuthorizeView>

Role/policy variants:

razor
<AuthorizeView Roles="Admin,Manager">    <Authorized>Admin content here</Authorized></AuthorizeView>

Access auth state in code

csharp
[CascadingParameter]private Task<AuthenticationState>? AuthState { get; set; }
protected override async Task OnInitializedAsync(){    if (AuthState is not null)    {        var state = await AuthState;        var isAdmin = state.User.IsInRole("Admin");    }}

Step 5 — Identity pages must stay static SSR

SignInManager and UserManager use HttpContext internally and throw in interactive components. Identity pages (login, register, manage) must render as static SSR.

In a globally interactive app, mark every Identity page:

razor
@page "/Account/Login"@attribute [ExcludeFromInteractiveRouting]

This forces a full-page navigation (exits the interactive circuit) so the page renders through the static SSR pipeline with a real HttpContext.

App.razor must use AcceptsInteractiveRouting() (Step 3) to return null for these pages — otherwise the framework still tries to render them interactively.

In a per-page app, Identity pages are static by default (no @rendermode directive), so [ExcludeFromInteractiveRouting] is not needed.

Step 6 — Auth state in WebAssembly / Auto mode

WebAssembly components run in the browser and have no HttpContext. Auth state must be serialized from the server during prerendering and deserialized on the client.

Server Program.cs:

csharp
builder.Services.AddAuthenticationStateSerialization();

Client .Client/Program.cs:

csharp
builder.Services.AddAuthenticationStateDeserialization();

Without these calls, Task<AuthenticationState> resolves to an anonymous user after WebAssembly takes over from prerendering.

AddAuthenticationStateSerialization accepts options to include role and claim data:

csharp
builder.Services.AddAuthenticationStateSerialization(options =>    options.SerializeAllClaims = true);

Render Mode × Auth Matrix

Render modeHttpContext.UserSignInManagerAuth state sourceKey requirement
Static SSRAvailableWorksServer pipelineUse middleware for redirects, <NotAuthorized> does NOT render
Server (interactive)NOT availableThrowsCascadingAuthenticationStateUse [Authorize] + AuthorizeView, not HttpContext
WebAssemblyNOT availableThrowsSerialized from serverAddAuthenticationStateSerialization / Deserialization
AutoNOT available after WASMThrowsSerialized from serverSame as WebAssembly; register in both Program.cs files

Common Mistakes

MistakeSymptomFix
Using HttpContext.User in interactive componentNull or stale claimsUse [CascadingParameter] Task<AuthenticationState>
SignInManager in interactive componentInvalidOperationExceptionMove to static SSR page with [ExcludeFromInteractiveRouting]
Missing AddAuthenticationStateSerializationAnonymous user after WASM loadsAdd to server Program.cs; add Deserialization to client Program.cs
<NotAuthorized> in static SSR layoutContent never shownStatic SSR uses middleware pipeline; redirect via LoginPath or RedirectToLogin component
Global interactivity without AcceptsInteractiveRoutingIdentity pages crashAdd AcceptsInteractiveRouting() check in App.razor (Step 3)
Missing AddCascadingAuthenticationState()Task<AuthenticationState> is nullRegister in Program.cs (Step 2)

来源与署名

来源:dotnet/skills位于plugins/dotnet-blazor/skills/configure-auth提交0608d89

许可证: MIT

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架