You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

部署Bicep脚本后ASP.NET Core的CORS配置失效问题排查

ARM模板(Bicep)导致ASP.NET Core CORS失效的原因及解决方法

问题背景

我们将ASP.NET Core Web API部署在Azure Web App中,初次部署后一切正常。但重新部署用于创建Web App的Bicep基础设施脚本后,CORS配置似乎丢失,API开始拒绝跨域请求。重启Web App无法解决该问题,但重新部署API则可以恢复。我们尝试通过启停Web App来触发该故障,但并未成功。我们并未在Web App上配置CORS,请问ARM模板为何会导致ASP.NET Core的CORS失效?

API中的CORS配置代码

(...)
var MyAllowSpecificOrigins = "_myAllowSpecificOrigins";

builder.Services.AddCors(options =>
{
    List<string> allowedOrigins = ["url"];

    options.AddPolicy(name: MyAllowSpecificOrigins,
                      policy =>
                      {
                          policy
                            .WithOrigins([.. allowedOrigins])
                            .AllowAnyMethod()
                            .AllowAnyHeader();
                      });
});
(...)

var app = builder.Build();

app.UseExceptionHandler();

// Configure the HTTP request pipeline.
if (app.Environment.IsDevelopment())
{
    app.UseSwagger();
    app.UseSwaggerUI();
}

app.UseCors(MyAllowSpecificOrigins);

app.UseAuthentication();
app.UseAuthorization();

app.MapControllers()
    .RequireAuthorization();

app.Run();

Web App的Bicep模板代码

resource appServicePlan 'Microsoft.Web/serverfarms@2023-01-01' = {
  name: appServicePlanName
  location: location
  properties: {
    reserved: false
  }
  sku: {
    ...
  }
}

resource apiService 'Microsoft.Web/sites@2023-01-01' = {
  name: apiAppName
  location: location
  identity: {
    type: 'SystemAssigned'
  }  
  properties: {
    httpsOnly: true
    serverFarmId: appServicePlan.id
    siteConfig: {
      alwaysOn: true
      http20Enabled: true
      appSettings:[
        {
          name: 'APPLICATIONINSIGHTS_CONNECTION_STRING'
          value: applicationInsights.properties.ConnectionString
        }
        {
          name: 'ApplicationInsightsAgent_EXTENSION_VERSION'
          value: '~2'
        }
      ]
    } 
  }
}

resource apiServiceSiteConfig 'Microsoft.Web/sites/config@2023-01-01' = {
  parent: apiService
  name: 'web'
  properties: {
    cors: null
    netFrameworkVersion: 'v8.0'
    use32BitWorkerProcess: false
    webSocketsEnabled: true
    alwaysOn: true
    managedPipelineMode: 'Integrated'
    http20Enabled: true
    minTlsVersion: '1.2'
    scmMinTlsVersion: '1.2'
    ftpsState: 'FtpsOnly'
    localMySqlEnabled: false
  }
}

问题根源

关键原因在于Bicep模板中apiServiceSiteConfig资源的cors: null设置。

Azure Web App自身提供了网关层面的CORS配置功能,当你在Bicep中显式设置cors: null时,会将Web App的CORS配置强制重置为空允许列表。此时,Azure Web App的网关会优先处理CORS校验,向响应中添加不符合业务需求的CORS头(如Access-Control-Allow-Origin: null),甚至直接拒绝跨域请求,导致ASP.NET Core中间件生成的合法CORS响应头被覆盖或忽略,最终前端浏览器判定跨域请求不合法。

重新部署API时,部署流程会重置Web App的部分站点配置(包括清除显式设置的CORS空值),让ASP.NET Core的CORS中间件重新获得响应头的控制权,因此CORS功能恢复正常。而单纯重启Web App不会修改已被Bicep固化的siteconfig配置,所以无法解决问题。

解决方法

  • 移除cors: null配置:直接从Bicep的apiServiceSiteConfig的properties中删除cors: null这一行。Web App会保持默认的CORS配置(不启用网关层面的CORS拦截),ASP.NET Core的CORS中间件就能正常处理跨域请求。
  • 避免不必要的配置覆盖:如果需要维护siteconfig中的其他属性,只需保留必要配置项即可,不要主动设置cors属性,防止干扰应用层的CORS逻辑。

内容的提问来源于stack exchange,提问作者Kasper Holdum

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.17 15:55:00