Microsoft.AspNetCore.Server.IIS.Core.IISHttpContextOfT Middleware C# .NET Core 2.2

Viewed 783

I have a .NET Core 2.2 C# API which randomly crashes with the following:

2020-08-07 10:44:42.039 +00:00 [Error] Exception occurred while processing message.
System.OperationCanceledException: The operation was canceled.
   at System.Threading.CancellationToken.ThrowOperationCanceledException()
   at System.Threading.SemaphoreSlim.WaitUntilCountOrTimeoutAsync(TaskNode asyncWaiter, Int32 millisecondsTimeout, CancellationToken cancellationToken)
   at Microsoft.IdentityModel.Protocols.ConfigurationManager`1.GetConfigurationAsync(CancellationToken cancel)
   at Microsoft.AspNetCore.Authentication.JwtBearer.JwtBearerHandler.HandleAuthenticateAsync()
2020-08-07 10:44:42.062 +00:00 [Error] Connection ID ""17798225728978863173"", Request ID ""8000c446-0000-f700-b63f-84710c7967bb"": An unhandled exception was thrown by the application.
System.OperationCanceledException: The operation was canceled.
   at System.Threading.CancellationToken.ThrowOperationCanceledException()
   at System.Threading.SemaphoreSlim.WaitUntilCountOrTimeoutAsync(TaskNode asyncWaiter, Int32 millisecondsTimeout, CancellationToken cancellationToken)
   at Microsoft.IdentityModel.Protocols.ConfigurationManager`1.GetConfigurationAsync(CancellationToken cancel)
   at Microsoft.AspNetCore.Authentication.JwtBearer.JwtBearerHandler.HandleAuthenticateAsync()
   at Microsoft.AspNetCore.Authentication.JwtBearer.JwtBearerHandler.HandleAuthenticateAsync()
   at Microsoft.AspNetCore.Authentication.AuthenticationHandler`1.AuthenticateAsync()
   at Microsoft.AspNetCore.Authentication.AuthenticationService.AuthenticateAsync(HttpContext context, String scheme)
   at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)
   at Microsoft.AspNetCore.StaticFiles.StaticFileMiddleware.Invoke(HttpContext context)
   at Swashbuckle.AspNetCore.SwaggerUI.SwaggerUIMiddleware.Invoke(HttpContext httpContext)
   at Swashbuckle.AspNetCore.Swagger.SwaggerMiddleware.Invoke(HttpContext httpContext, ISwaggerProvider swaggerProvider)
   at Microsoft.AspNetCore.Server.IIS.Core.IISHttpContextOfT`1.ProcessRequestAsync()

I cannot recreate this issue in another environment. This looks to me like there are problems in the middleware (or maybe Authentication)

I have inherited the project and noticed the middleware might not be in the right order: Startup.cs:

public void Configure(IApplicationBuilder app, IHostingEnvironment env)
        {
            if (env.IsDevelopment())
            {
                app.UseDeveloperExceptionPage();
            }

            // swagger
            app.UseSwagger();
            app.UseSwaggerUI(options => options.ConfigureSwaggerUi(this.Configuration));

            // versioning
            app.UseCustomApiVersionHeader(this.Configuration);

            // authentication
            app.UseAuthentication();

            // static files
            app.UseStaticFiles();

            app.UseMvc();
        }

I also have a custom authentication service:

public void ConfigureServices(IServiceCollection services)
 {
...
services.AddCustomAuthentication(this.Configuration);
...
}

AuthenticationIoC:

namespace Authentication.Api.Middleware
{
    public static class CustomAuthenticationIoc
    {
        public static IServiceCollection AddCustomAuthentication(this IServiceCollection services, IConfiguration configuration)
        {
            var domain = $"https://{configuration["security:domain"]}/";

            services.AddAuthentication(options =>
            {
                options.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
                options.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
            }).AddJwtBearer(options =>
            {
                options.Authority = $"https://{configuration["security:domain"]}/";
                options.Audience = configuration["security:audience"];
            });

            // get all policies
            var policies = configuration["security:policies"]?
                .Split(' ', StringSplitOptions.RemoveEmptyEntries)?
                .ToList();

            services.AddAuthorization(configure: options =>
            {
                foreach (var policyItem in policies)
                {
                    options.AddPolicy(policyItem,
                        policy => policy.Requirements.Add(new HasScopeRequirement(policyItem, domain)));
                }
            });

            // register the scope authorization handler
            services.AddSingleton<IAuthorizationHandler, HasScopeHandler>();

            return services;
        }
    }
}

Any help would be appreciated as I have explored a lot of different roots: Environmental, Authentication, and JWT Swagger etc.

2 Answers

(Edited months later... This didn't solve the issue)

I'm nearly certain this was a bug in the Microsoft.AspNetCore.Authentication.x 3.1.4 or 3.1.5 packages. I've been getting this error rarely since July 2020 when I installed those packages and I've been seeing it here and there ever since. I upgraded to 3.1.14 a couple weeks ago and I haven't seen it in my logs for a week.

It is happened when client(Browser, Aplication) cancelling request, then your web app cancel this request, job.

Related