MSDN explicitly says it should do 401 redirect, but I\'m getting a 302 redirect on FF, and this is causing problems in AJAX requests as the returned status is 200 (from the red
If you are using a ASP.NET MVC 5 Web Application go to App_Start
-> Startup.Auth.cs
. Check if app.UseCookieAuthentication
is enabled and see if CookieAuthenticationOptions
is set to LoginPath = new PathString("/Login"),
or similar. If you remove this parameter 401
will stop redirecting.
Description for LoginPath
:
The LoginPath property informs the middleware that it should change an outgoing 401 Unauthorized status code into a 302 redirection onto the given login path. The current url which generated the 401 is added to the LoginPath as a query string parameter named by the ReturnUrlParameter. Once a request to the LoginPath grants a new SignIn identity, the ReturnUrlParameter value is used to redirect the browser back to the url which caused the original unauthorized status code. If the LoginPath is null or empty, the middleware will not look for 401 Unauthorized status codes, and it will not redirect automatically when a login occurs.