You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core仅谷歌认证出现循环重定向及关联失败问题

ASP.NET Core集成Identity后谷歌认证循环重定向及Correlation失败问题解决

问题场景

我们有一个集成ASP.NET Core Identity的ASP.NET Core应用,期望仅通过谷歌完成用户认证(不提供登录表单)。原认证配置如下:

services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme;
})
.AddCookie()
.AddGoogle(options =>
{
    options.ClientId = Configuration["Authentication:Google:ClientId"];
    options.ClientSecret = Configuration["Authentication:Google:ClientSecret"];
});

// ....

app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

// ....

HomeController代码:

[Authorize]
public class HomeController : BaseController
{
    public HomeController()
    {
    }

    public IActionResult Index()
    {
       return View();
    }
}

未调用以下ASP.NET Core Identity配置代码时,应用运行正常:

services.AddIdentity<User, Role>()
    .AddErrorDescriber<LocalizedIdentityErrorDescriber>()
    .AddEntityFrameworkStores<ApplicationDbContext>()
    .AddDefaultTokenProviders();

但添加该Identity配置后,应用会在首页Index与谷歌认证页面间循环重定向多次,最终抛出认证失败异常:

An unhandled exception occurred while processing the request.

AuthenticationFailureException: Correlation failed. Unknown location

AuthenticationFailureException: An error was encountered while handling the remote login.

同时signin-google组件无法设置认证Cookie。

问题原因

AddIdentity方法会自动配置基于Cookie的认证,默认使用的Scheme是IdentityConstants.ApplicationScheme,这与手动配置的CookieAuthenticationDefaults.AuthenticationScheme产生冲突。当触发认证流程时,两套Cookie认证配置的Scheme不一致,导致谷歌认证的关联验证(Correlation)失败,无法正确生成或读取认证Cookie,进而引发循环重定向。

解决方案

1. 统一Cookie认证Scheme

将Identity的Cookie Scheme与手动配置的认证Scheme统一,有两种实现方式:

方式一:让Identity使用自定义的Cookie Scheme

修改AddIdentity的配置,指定其Cookie认证使用预设的Scheme:

services.AddIdentity<User, Role>()
    .AddErrorDescriber<LocalizedIdentityErrorDescriber>()
    .AddEntityFrameworkStores<ApplicationDbContext>()
    .AddDefaultTokenProviders()
    // 指定Identity的Cookie认证Scheme为自定义的Cookie Scheme
    .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme, options =>
    {
        // 可按需配置Cookie属性,比如名称、过期时间等
        options.Cookie.Name = ".AspNetCore.MyAppCookie";
    });

// 保持原Authentication配置不变
services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme;
})
.AddGoogle(options =>
{
    options.ClientId = Configuration["Authentication:Google:ClientId"];
    options.ClientSecret = Configuration["Authentication:Google:ClientSecret"];
});

方式二:将全局认证默认Scheme改为Identity的默认Scheme

调整AddAuthentication的配置,使用Identity的默认Scheme作为全局默认,并指定谷歌认证回调后的登录Scheme:

services.AddIdentity<User, Role>()
    .AddErrorDescriber<LocalizedIdentityErrorDescriber>()
    .AddEntityFrameworkStores<ApplicationDbContext>()
    .AddDefaultTokenProviders();

services.AddAuthentication(options =>
{
    options.DefaultScheme = IdentityConstants.ApplicationScheme;
    options.DefaultChallengeScheme = GoogleDefaults.AuthenticationScheme;
})
.AddGoogle(options =>
{
    options.ClientId = Configuration["Authentication:Google:ClientId"];
    options.ClientSecret = Configuration["Authentication:Google:ClientSecret"];
    // 指定谷歌认证成功后使用Identity的Cookie Scheme登录
    options.SignInScheme = IdentityConstants.ApplicationScheme;
});

2. 移除重复的Cookie认证配置

由于AddIdentity已经自动添加了Cookie认证,原配置中的.AddCookie()可以移除,避免重复配置引发冲突。

3. 确认中间件顺序与回调路径

确保中间件顺序正确:app.UseRouting() → app.UseAuthentication() → app.UseAuthorization(),且谷歌认证的默认回调路径/signin-google未被其他路由拦截。

验证效果

修改配置后重新启动应用,访问首页会自动跳转到谷歌认证页面,完成认证后将正确设置Identity认证Cookie,不再出现循环重定向,Correlation失败的异常也会消失。

内容的提问来源于stack exchange,提问作者Mohammed Wafy

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 15:00:05