.NET Core Identity Cookie无法被Yarp API通过数据库DataProtectionKeys验证
问题
我有一个非直接面向互联网的.NET Core Identity API,Yarp API是面向互联网的入口,希望通过Identity Cookie判断用户是否已登录,未登录则重定向至登录页。
已将Identity API的DataProtection密钥存储到数据库,供所有Identity实例访问:
services.AddDataProtection().PersistKeysToDbContext<ApplicationDbContext>();
一切正常,能在Identity数据库的DataProtectionKey表中看到密钥。
现在想在Yarp API中添加中间件,检查.AspNetCore.Identity.Application Cookie是否存在且有效,若无效则将请求重定向至Identity的登录页(登录路径已被中间件允许)。
在Yarp API中配置了相同的数据库存储密钥的代码,以及Cookie认证:
services.AddDataProtection().PersistKeysToDbContext<ApplicationDbContext>(); services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme; }).AddCookie();
尝试了两种方式均未成功:
- 使用
AuthenticateAsync:
var authResult = await context.AuthenticateAsync(CookieAuthenticationDefaults.AuthenticationScheme);
- 手动解析Cookie:
TicketDataFormat ticketDataFormat = new TicketDataFormat(dataProtector); AuthenticationTicket ticket = ticketDataFormat.Unprotect(cookieContent); // 能看到cookieContent是加密字符串
解决方案
1. 对齐Cookie认证与Identity的配置参数
Identity的.AspNetCore.Identity.Application Cookie有专属配置规则,Yarp端必须完全匹配才能解析,需显式指定关键参数并同步DataProtection配置:
// 先配置DataProtection,确保应用名称与Identity端完全一致 services.AddDataProtection() .PersistKeysToDbContext<ApplicationDbContext>() .SetApplicationName("YourSharedAppName"); // 替换为Identity API中设置的应用名称 services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme; }) .AddCookie(CookieAuthenticationDefaults.AuthenticationScheme, options => { // 匹配Identity的Cookie名称 options.Cookie.Name = ".AspNetCore.Identity.Application"; // 同步Cookie路径,通常为"/" options.Cookie.Path = "/"; // 跨域场景下需配置Domain(与Identity端一致) // options.Cookie.Domain = "yourdomain.com"; // 指定登录跳转路径 options.LoginPath = "/Account/Login"; // 替换为实际Identity登录页路径 // 使用与Identity一致的TicketDataFormat保护规则 options.TicketDataFormat = new TicketDataFormat( services.BuildServiceProvider().GetRequiredService<IDataProtectionProvider>() .CreateProtector("Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationMiddleware", CookieAuthenticationDefaults.AuthenticationScheme, "v2")); });
2. 使用官方授权中间件替代自定义逻辑
无需手动编写Cookie解析代码,直接利用官方授权中间件自动处理认证与重定向:
在Yarp的Program.cs管道中添加授权中间件(需放在路由配置之前):
app.UseAuthentication(); app.UseAuthorization(); // 配置Yarp路由 app.MapReverseProxy();
然后为需要保护的路由添加授权限制,可全局配置:
// 全局要求所有反向代理请求需认证 app.MapReverseProxy().RequireAuthorization();
未登录用户会自动重定向至配置的登录页。
3. 检查DataProtection密钥访问权限
确认Yarp API的数据库连接字符串拥有DataProtectionKey表的读取权限,否则无法获取密钥完成Cookie解密。
4. 验证Cookie传输有效性
- 检查请求头的
Cookie字段是否包含.AspNetCore.Identity.Application - 跨域场景下,需确保Identity端设置
Cookie.SameSite = SameSiteMode.None并启用HTTPS,避免Cookie被浏览器拦截
内容的提问来源于stack exchange,提问作者DanM
相关产品推荐
相关产品推荐

