ASP.NET Core仅谷歌认证出现循环重定向及关联失败问题
问题场景
我们有一个集成ASP.NET Core Identity的ASP.NET Core应用,期望仅通过谷歌完成用户认证(不提供登录表单)。原认证配置如下:
services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme; }) .AddCookie() .AddGoogle(options => { options.ClientId = Configuration["Authentication:Google:ClientId"]; options.ClientSecret = Configuration["Authentication:Google:ClientSecret"]; }); // .... app.UseRouting(); app.UseAuthentication(); app.UseAuthorization(); // ....
HomeController代码:
[Authorize] public class HomeController : BaseController { public HomeController() { } public IActionResult Index() { return View(); } }
未调用以下ASP.NET Core Identity配置代码时,应用运行正常:
services.AddIdentity<User, Role>() .AddErrorDescriber<LocalizedIdentityErrorDescriber>() .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultTokenProviders();
但添加该Identity配置后,应用会在首页Index与谷歌认证页面间循环重定向多次,最终抛出认证失败异常:
An unhandled exception occurred while processing the request.
AuthenticationFailureException: Correlation failed. Unknown location
AuthenticationFailureException: An error was encountered while handling the remote login.
同时signin-google组件无法设置认证Cookie。
问题原因
AddIdentity方法会自动配置基于Cookie的认证,默认使用的Scheme是IdentityConstants.ApplicationScheme,这与手动配置的CookieAuthenticationDefaults.AuthenticationScheme产生冲突。当触发认证流程时,两套Cookie认证配置的Scheme不一致,导致谷歌认证的关联验证(Correlation)失败,无法正确生成或读取认证Cookie,进而引发循环重定向。
解决方案
1. 统一Cookie认证Scheme
将Identity的Cookie Scheme与手动配置的认证Scheme统一,有两种实现方式:
方式一:让Identity使用自定义的Cookie Scheme
修改AddIdentity的配置,指定其Cookie认证使用预设的Scheme:
services.AddIdentity<User, Role>() .AddErrorDescriber<LocalizedIdentityErrorDescriber>() .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultTokenProviders() // 指定Identity的Cookie认证Scheme为自定义的Cookie Scheme .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme, options => { // 可按需配置Cookie属性,比如名称、过期时间等 options.Cookie.Name = ".AspNetCore.MyAppCookie"; }); // 保持原Authentication配置不变 services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme; }) .AddGoogle(options => { options.ClientId = Configuration["Authentication:Google:ClientId"]; options.ClientSecret = Configuration["Authentication:Google:ClientSecret"]; });
方式二:将全局认证默认Scheme改为Identity的默认Scheme
调整AddAuthentication的配置,使用Identity的默认Scheme作为全局默认,并指定谷歌认证回调后的登录Scheme:
services.AddIdentity<User, Role>() .AddErrorDescriber<LocalizedIdentityErrorDescriber>() .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultTokenProviders(); services.AddAuthentication(options => { options.DefaultScheme = IdentityConstants.ApplicationScheme; options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme; }) .AddGoogle(options => { options.ClientId = Configuration["Authentication:Google:ClientId"]; options.ClientSecret = Configuration["Authentication:Google:ClientSecret"]; // 指定谷歌认证成功后使用Identity的Cookie Scheme登录 options.SignInScheme = IdentityConstants.ApplicationScheme; });
2. 移除重复的Cookie认证配置
由于AddIdentity已经自动添加了Cookie认证,原配置中的.AddCookie()可以移除,避免重复配置引发冲突。
3. 确认中间件顺序与回调路径
确保中间件顺序正确:app.UseRouting() → app.UseAuthentication() → app.UseAuthorization(),且谷歌认证的默认回调路径/signin-google未被其他路由拦截。
验证效果
修改配置后重新启动应用,访问首页会自动跳转到谷歌认证页面,完成认证后将正确设置Identity认证Cookie,不再出现循环重定向,Correlation失败的异常也会消失。
内容的提问来源于stack exchange,提问作者Mohammed Wafy

