You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Docker中运行AzureAD认证ASP.NET Core MVC应用报错

Fixes for AzureAD Auth Errors in Dockerized ASP.NET Core MVC App

1. Resolve "Correlation failed." Error

This error typically stems from mismatched request context between the external client and the containerized app.

  • Configure Forward Headers: Since Docker forwards requests from port 8080 to port 80 inside the container, the app needs to recognize the external host/port. Add this middleware in Program.cs (before authentication middleware):
    app.UseForwardedHeaders(new ForwardedHeadersOptions
    {
        ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedProto
    });
    
  • Validate AzureAD Redirect URI: Ensure the redirect URI in your AzureAD app registration exactly matches http://localhost:8080/signin-oidc (include the correct scheme, no trailing slashes). Double-check that ClientId and TenantId in appsettings.json match AzureAD values.
  • Update Allowed Hosts: In appsettings.json, set "AllowedHosts": "*" (or specific hosts) to avoid blocking localhost requests.

2. Fix "Unable to unprotect the message.State." Error

This issue relates to lost data protection keys when containers restart. By default, ASP.NET Core uses an in-memory key ring that doesn't persist across container runs.

  • Persist Data Protection Keys: For local testing, mount a volume to store keys outside the container. Add this to your docker run command:
    -v ${HOME}/aspnet-dataprotection:/var/aspnet/DataProtection-Keys
    
    Then configure data protection in Program.cs to use this directory:
    builder.Services.AddDataProtection()
        .PersistKeysToFileSystem(new DirectoryInfo("/var/aspnet/DataProtection-Keys"))
        .SetApplicationName("YourAppName"); // Use your actual app name
    
  • Adjust Cookie Policy Settings: Ensure cookie policy aligns with AzureAD's requirements. Configure this in Program.cs:
    builder.Services.Configure<CookiePolicyOptions>(options =>
    {
        options.MinimumSameSitePolicy = SameSiteMode.Unspecified;
        options.OnAppendCookie = ctx => ctx.CookieOptions.SameSite = SameSiteMode.None;
        options.OnDeleteCookie = ctx => ctx.CookieOptions.SameSite = SameSiteMode.None;
        options.Secure = CookieSecurePolicy.None; // Use "Always" in production with HTTPS
    });
    
    Place app.UseCookiePolicy(); before app.UseAuthentication(); and app.UseAuthorization();.

3. Additional Troubleshooting Steps

  • Clear Browser Cookies: Old auth cookies from previous runs can cause conflicts. Delete all localhost-related cookies before retesting.
  • Enable Detailed Logging: In appsettings.json, set verbose logging to debug auth flow issues:
    "Logging": {
        "LogLevel": {
            "Microsoft.AspNetCore.Authentication": "Debug",
            "Microsoft": "Information"
        }
    }
    
  • Check Container Network Access: Verify the container can reach AzureAD by running curl https://login.microsoftonline.com inside the container.

内容的提问来源于stack exchange,提问作者Kyle Barnes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 15:53:28