You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core Identity Cookie无法被Yarp API通过数据库DataProtectionKeys验证

问题

我有一个非直接面向互联网的.NET Core Identity API,Yarp API是面向互联网的入口,希望通过Identity Cookie判断用户是否已登录,未登录则重定向至登录页。

已将Identity API的DataProtection密钥存储到数据库,供所有Identity实例访问:

services.AddDataProtection().PersistKeysToDbContext<ApplicationDbContext>();

一切正常,能在Identity数据库的DataProtectionKey表中看到密钥。

现在想在Yarp API中添加中间件,检查.AspNetCore.Identity.Application Cookie是否存在且有效,若无效则将请求重定向至Identity的登录页(登录路径已被中间件允许)。

在Yarp API中配置了相同的数据库存储密钥的代码,以及Cookie认证:

services.AddDataProtection().PersistKeysToDbContext<ApplicationDbContext>();
services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme;
}).AddCookie();

尝试了两种方式均未成功:

  1. 使用AuthenticateAsync:
var authResult = await context.AuthenticateAsync(CookieAuthenticationDefaults.AuthenticationScheme);
  1. 手动解析Cookie:
TicketDataFormat ticketDataFormat = new TicketDataFormat(dataProtector);
AuthenticationTicket ticket = ticketDataFormat.Unprotect(cookieContent); 
// 能看到cookieContent是加密字符串

解决方案

1. 对齐Cookie认证与Identity的配置参数

Identity的.AspNetCore.Identity.Application Cookie有专属配置规则,Yarp端必须完全匹配才能解析,需显式指定关键参数并同步DataProtection配置:

// 先配置DataProtection,确保应用名称与Identity端完全一致
services.AddDataProtection()
    .PersistKeysToDbContext<ApplicationDbContext>()
    .SetApplicationName("YourSharedAppName"); // 替换为Identity API中设置的应用名称

services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = CookieAuthenticationDefaults.AuthenticationScheme;
})
.AddCookie(CookieAuthenticationDefaults.AuthenticationScheme, options =>
{
    // 匹配Identity的Cookie名称
    options.Cookie.Name = ".AspNetCore.Identity.Application";
    // 同步Cookie路径,通常为"/"
    options.Cookie.Path = "/";
    // 跨域场景下需配置Domain(与Identity端一致)
    // options.Cookie.Domain = "yourdomain.com";
    // 指定登录跳转路径
    options.LoginPath = "/Account/Login"; // 替换为实际Identity登录页路径
    // 使用与Identity一致的TicketDataFormat保护规则
    options.TicketDataFormat = new TicketDataFormat(
        services.BuildServiceProvider().GetRequiredService<IDataProtectionProvider>()
            .CreateProtector("Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationMiddleware", 
                CookieAuthenticationDefaults.AuthenticationScheme, "v2"));
});

2. 使用官方授权中间件替代自定义逻辑

无需手动编写Cookie解析代码,直接利用官方授权中间件自动处理认证与重定向:
在Yarp的Program.cs管道中添加授权中间件(需放在路由配置之前):

app.UseAuthentication();
app.UseAuthorization();

// 配置Yarp路由
app.MapReverseProxy();

然后为需要保护的路由添加授权限制,可全局配置:

// 全局要求所有反向代理请求需认证
app.MapReverseProxy().RequireAuthorization();

未登录用户会自动重定向至配置的登录页。

3. 检查DataProtection密钥访问权限

确认Yarp API的数据库连接字符串拥有DataProtectionKey表的读取权限,否则无法获取密钥完成Cookie解密。

4. 验证Cookie传输有效性

  • 检查请求头的Cookie字段是否包含.AspNetCore.Identity.Application
  • 跨域场景下,需确保Identity端设置Cookie.SameSite = SameSiteMode.None并启用HTTPS,避免Cookie被浏览器拦截

内容的提问来源于stack exchange,提问作者DanM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 10:56:09