You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ASP.NET Core MVC 2.0无Identity跨应用Cookie认证问题求助

Alright, let's break down why your app1-created cookie isn't readable in app2 and how to fix it. The core issue here is that each ASP.NET Core app uses its own isolated data protection system by default—so app2 can't decrypt the cookie app1 encrypted with its unique set of keys. Here's a step-by-step solution:

1. Share Data Protection Configuration Between Apps

The key to making cross-app cookie auth work is ensuring both apps use the same data protection keys and setup. This lets them encrypt/decrypt cookies interchangeably.

Update ConfigureServices in Both Apps

Add this configuration before your AddAuthentication setup in both Startup.cs files:

using Microsoft.AspNetCore.DataProtection;
using System.IO;

public void ConfigureServices(IServiceCollection services)
{
    // Configure shared data protection first
    services.AddDataProtection()
        // Store keys in a shared directory (create this folder first, and ensure both apps have read/write access)
        .PersistKeysToFileSystem(new DirectoryInfo(@"C:\SharedCookieKeys"))
        // Use the same application name for both apps to share the key ring
        .SetApplicationName("MySharedCookieApp");

    // Your existing MVC and auth setup
    services.AddMvc();
    services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme)
        .AddCookie(options =>
        {
            options.Cookie.Domain = "localhost";
            options.Cookie.Name = "mycookie";
            options.Cookie.Path = "/";
            options.Cookie.HttpOnly = true;
            options.Cookie.SameSite = Microsoft.AspNetCore.Http.SameSiteMode.Lax;
            // For local HTTP testing: disable secure cookie requirement (remove this in production!)
            options.Cookie.SecurePolicy = CookieSecurePolicy.None;
        });
}

Key Notes:

  • The shared directory (C:\SharedCookieKeys) needs to exist, and both apps must have permission to read/write to it.
  • SetApplicationName must be identical in both apps—this tells the data protection system they belong to the same "group" and should share keys.

2. Double-Check Critical Setup Details

Make sure these boxes are ticked to avoid common pitfalls:

  • Middleware Order: You already have app.UseAuthentication() before app.UseMvc()—that's correct, since authentication needs to run before MVC processes requests.
  • Cookie Consistency: All cookie properties (Domain, Name, Path, etc.) must match exactly between the two apps. The SecurePolicy addition is vital for local HTTP testing (browsers won't send secure cookies over unencrypted connections).
  • Port Configuration: Run app1 and app2 on different ports under localhost (e.g., https://localhost:5000 and https://localhost:5001). Same-domain (localhost) different ports are allowed to share cookies.

3. Test the Fixed Setup

  1. Run app1, log in to generate the mycookie cookie.
  2. Open your browser's developer tools (F12 → Application tab → Cookies → localhost) to confirm the cookie exists with the correct name and domain.
  3. Navigate to app2's URL, and check if the cookie is sent in the request (Network tab → select the request → Cookies section).
  4. In app2's controller, HttpContext.User.Claims should now populate with the claims from app1's cookie.

Why This Works

By sharing the data protection keys and application name, both apps use the same encryption/decryption logic. This breaks the default isolation and allows them to recognize each other's authenticated cookies.

内容的提问来源于stack exchange,提问作者Vicky

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:23:15