Warning: file_get_contents(/data/phpspider/zhask/data//catemap/1/asp.net/35.json): failed to open stream: No such file or directory in /data/phpspider/zhask/libs/function.php on line 167

Warning: Invalid argument supplied for foreach() in /data/phpspider/zhask/libs/tag.function.php on line 1116

Notice: Undefined index: in /data/phpspider/zhask/libs/function.php on line 180

Warning: array_chunk() expects parameter 1 to be array, null given in /data/phpspider/zhask/libs/function.php on line 181

Warning: file_get_contents(/data/phpspider/zhask/data//catemap/3/html/69.json): failed to open stream: No such file or directory in /data/phpspider/zhask/libs/function.php on line 167

Warning: Invalid argument supplied for foreach() in /data/phpspider/zhask/libs/tag.function.php on line 1116

Notice: Undefined index: in /data/phpspider/zhask/libs/function.php on line 180

Warning: array_chunk() expects parameter 1 to be array, null given in /data/phpspider/zhask/libs/function.php on line 181
Asp.net validateRequest=";假;不工作,即使使用requestValidationMode=";2.0“;_Asp.net_Azure_Wif - Fatal编程技术网

Asp.net validateRequest=";假;不工作,即使使用requestValidationMode=";2.0“;

Asp.net validateRequest=";假;不工作,即使使用requestValidationMode=";2.0“;,asp.net,azure,wif,Asp.net,Azure,Wif,我有一个ASP.NET网站在Visual Studio开发结构(azure项目)中运行,并且正在使用ACS和WIF。我的身份验证过程不起作用,因为我登录后收到以下信息: A potentially dangerous Request.Form value was detected from the client (wresult="<t:RequestSecurityTo..."). 一个潜在危险的请求。从客户端检测到表单值(wresult=“我没有意识到,但我意外地在WIF创建的位置

我有一个ASP.NET网站在Visual Studio开发结构(azure项目)中运行,并且正在使用ACS和WIF。我的身份验证过程不起作用,因为我登录后收到以下信息:

A potentially dangerous Request.Form value was detected from the client (wresult="<t:RequestSecurityTo..."). 

一个潜在危险的请求。从客户端检测到表单值(wresult=“我没有意识到,但我意外地在WIF创建的位置标记中添加了这些设置:

  <location path="FederationMetadata">
    <system.web>
      <authorization>
        <allow users="*" />
      </authorization>
      <!-- wrong! -->
    </system.web>
  </location>
  <system.web>
      <!-- right! -->
    <httpRuntime requestValidationMode="2.0" />
    <pages validateRequest="false" />


您是否在应用程序之外的页面上发布?为什么不改用requestsValidationType?如果每次发生这种情况时我都有一枚硬币……无论如何,这里有一个有用的链接:,您也可以接受自己的答案。
<httpRuntime requestValidationMode="2.0" />
  <location path="FederationMetadata">
    <system.web>
      <authorization>
        <allow users="*" />
      </authorization>
      <!-- wrong! -->
    </system.web>
  </location>
  <system.web>
      <!-- right! -->
    <httpRuntime requestValidationMode="2.0" />
    <pages validateRequest="false" />