ASP.NET Core MVC 2.0无Identity跨应用Cookie认证问题求助
Alright, let's break down why your app1-created cookie isn't readable in app2 and how to fix it. The core issue here is that each ASP.NET Core app uses its own isolated data protection system by default—so app2 can't decrypt the cookie app1 encrypted with its unique set of keys. Here's a step-by-step solution:
1. Share Data Protection Configuration Between Apps
The key to making cross-app cookie auth work is ensuring both apps use the same data protection keys and setup. This lets them encrypt/decrypt cookies interchangeably.
Update ConfigureServices in Both Apps
Add this configuration before your AddAuthentication setup in both Startup.cs files:
using Microsoft.AspNetCore.DataProtection; using System.IO; public void ConfigureServices(IServiceCollection services) { // Configure shared data protection first services.AddDataProtection() // Store keys in a shared directory (create this folder first, and ensure both apps have read/write access) .PersistKeysToFileSystem(new DirectoryInfo(@"C:\SharedCookieKeys")) // Use the same application name for both apps to share the key ring .SetApplicationName("MySharedCookieApp"); // Your existing MVC and auth setup services.AddMvc(); services.AddAuthentication(CookieAuthenticationDefaults.AuthenticationScheme) .AddCookie(options => { options.Cookie.Domain = "localhost"; options.Cookie.Name = "mycookie"; options.Cookie.Path = "/"; options.Cookie.HttpOnly = true; options.Cookie.SameSite = Microsoft.AspNetCore.Http.SameSiteMode.Lax; // For local HTTP testing: disable secure cookie requirement (remove this in production!) options.Cookie.SecurePolicy = CookieSecurePolicy.None; }); }
Key Notes:
- The shared directory (
C:\SharedCookieKeys) needs to exist, and both apps must have permission to read/write to it. SetApplicationNamemust be identical in both apps—this tells the data protection system they belong to the same "group" and should share keys.
2. Double-Check Critical Setup Details
Make sure these boxes are ticked to avoid common pitfalls:
- Middleware Order: You already have
app.UseAuthentication()beforeapp.UseMvc()—that's correct, since authentication needs to run before MVC processes requests. - Cookie Consistency: All cookie properties (
Domain,Name,Path, etc.) must match exactly between the two apps. TheSecurePolicyaddition is vital for local HTTP testing (browsers won't send secure cookies over unencrypted connections). - Port Configuration: Run app1 and app2 on different ports under
localhost(e.g.,https://localhost:5000andhttps://localhost:5001). Same-domain (localhost) different ports are allowed to share cookies.
3. Test the Fixed Setup
- Run app1, log in to generate the
mycookiecookie. - Open your browser's developer tools (F12 → Application tab → Cookies → localhost) to confirm the cookie exists with the correct name and domain.
- Navigate to app2's URL, and check if the cookie is sent in the request (Network tab → select the request → Cookies section).
- In app2's controller,
HttpContext.User.Claimsshould now populate with the claims from app1's cookie.
Why This Works
By sharing the data protection keys and application name, both apps use the same encryption/decryption logic. This breaks the default isolation and allows them to recognize each other's authenticated cookies.
内容的提问来源于stack exchange,提问作者Vicky

