You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

多租户MVC客户端集成IdentityServer4后allegion子域无限重定向求助

IdentityServer4多租户子域Cookie存储异常问题

我开发了用于管理客户端和用户的Identity Server Admin,以及负责身份认证的IdentityServer4,两款应用均基于Asp.Net Core 3.1开发。

Identity Server Admin是多租户应用,租户名称作为主机子域名使用。

我已将两个应用部署在Azure App Service上,Identity Server Admin(即MVC Client)和IdentityServer4均配置了自定义域名:

上述域名中,tenant1、tenant2两个子域运行正常,可顺利通过IdentityServer4完成认证并存储Cookie,但allegion子域无法存储Cookie,会陷入无限重定向循环。

以下是我在startup.cs中的Cookie配置代码:

services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = AuthenticationConsts.OidcAuthenticationScheme;

    options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultForbidScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultSignOutScheme = CookieAuthenticationDefaults.AuthenticationScheme;
})
.AddCookie(CookieAuthenticationDefaults.AuthenticationScheme,
    options =>
    {
        options.Cookie.Name = adminConfiguration.IdentityAdminCookieName;

        options.Cookie.SameSite = SameSiteMode.None;
        options.Cookie.HttpOnly = true;
        options.Cookie.SecurePolicy = CookieSecurePolicy.Always;
        options.Events = new CookieAuthenticationEvents
        {
            OnSignedIn = context => OnSignedIn(context, adminConfiguration, httpContextAccessor),
            OnSigningIn = context => OnSigningIn(context, adminConfiguration, httpContextAccessor),
            OnValidatePrincipal = context => OnValidatePrincipal(context, adminConfiguration, httpContextAccessor)
        };
    })

目前我暂未排查出问题原因,恳请大家帮忙提供解决方案,非常感谢。


内容的提问来源于stack exchange,提问作者Mahendran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.07 15:21:01