.NET Core与.NET 4.8共享ASP.NET Identity Cookie配置求助
我需要让.NET Core(.NET 6)的新登录页面和遗留.NET 4.8应用共享ASP.NET Identity Cookie,实现一处登出则两处同步登出。双方均使用最新版ASP.NET Identity,以下是我当前的配置代码:
.NET 6(登录页)配置
builder.Services.AddDataProtection() .PersistKeysToFileSystem(new DirectoryInfo(@"c:\temp\common")) //.ProtectKeysWithCertificate("thumbprint") .SetApplicationName("SharedCookieApp"); builder.Services.ConfigureApplicationCookie(options => { options.Cookie.HttpOnly = true; options.ExpireTimeSpan = TimeSpan.FromMinutes(10); options.SlidingExpiration = true; options.Cookie.SameSite = SameSiteMode.Lax; options.Cookie.Name = ".MyCookie"; });
.NET 4.8(遗留应用)配置
public void ConfigureAuth(IAppBuilder app) { // Enable the application to use a cookie to store information for the signed in user // and to use a cookie to temporarily store information about a user logging in with a third party login provider // Configure the sign in cookie app.UseCookieAuthentication(new CookieAuthenticationOptions { AuthenticationType = "Identity.Application", LoginPath = new PathString("/Account/Login"), Provider = new CookieAuthenticationProvider { }, // TODO: Need to make the Dataprotection work on Azure CookieName = ".AspNet.SharedCookie", CookieSameSite = Microsoft.Owin.SameSiteMode.Lax, CookieSecure = CookieSecureOption.Always, TicketDataFormat = new AspNetTicketDataFormat( new DataProtectorShim( DataProtectionProvider.Create(new DirectoryInfo(@"c:\temp\common"), builder => builder.SetApplicationName("SharedCookieApp"))//.ProtectKeysWithCertificate("thumbprint") // for production .CreateProtector( "Microsoft.AspNetCore.Authentication.Cookies.CookieAuthenticationMiddleware", // Must match the Scheme name used in the ASP.NET Core app, i.e. IdentityConstants.ApplicationScheme "Identity.Application", "v2"))), CookieManager = new Microsoft.Owin.Infrastructure.ChunkingCookieManager() }); app.UseTwoFactorSignInCookie(DefaultAuthenticationTypes.TwoFactorCookie, TimeSpan.FromMinutes(5)); app.UseTwoFactorRememberBrowserCookie(DefaultAuthenticationTypes.TwoFactorRememberBrowserCookie); }
我已创建包含上述代码的GitHub仓库,恳请有相关经验的开发者帮忙检查配置是否正确,并提供实现同步登出的建议与验证方案。
内容的提问来源于stack exchange,提问作者Philip Johnson
相关产品推荐
相关产品推荐

