You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用services.AddDataProtection()时ABP框架共享Cookie失效问题

Troubleshooting Shared Authentication Between Two ABP Zero .NET Core 3.1 Sites

Hey there, let's break down why your two ABP Zero-based sites (A and B) under the same domain aren't sharing authentication state. When you log into Site A but Site B still shows User.Identity?.IsAuthenticated = false on refresh, it almost always boils down to mismatched authentication configuration or missing cookie sharing setup. Here's how to fix it:

ABP Zero wraps ASP.NET Core's cookie authentication, so both sites need exact same settings to read each other's auth cookies.

  • Unify the Cookie Name & Authentication Scheme:
    By default, ABP Zero might use a scheme/cookie name tied to your project template (like MyCompanyNameAuth). Override this in both sites' ConfigureServices method to use a shared value:

    services.Configure<AbpAuthenticationOptions>(options =>
    {
        options.DefaultAuthenticateScheme = "SharedCompanyAuthScheme";
        options.DefaultSignInScheme = "SharedCompanyAuthScheme";
    });
    
    services.AddCookie("SharedCompanyAuthScheme", options =>
    {
        // Use a shared cookie name across both sites
        options.Cookie.Name = ".MyCompany.SharedAuthCookie";
        // Set the root domain so all subdomains can access it (e.g., if A is app1.yourdomain.com and B is app2.yourdomain.com)
        options.Cookie.Domain = ".yourdomain.com";
        // Ensure cookie is accessible across all paths
        options.Cookie.Path = "/";
        // Match other settings like expiration, SameSite, etc., between both sites
        options.Cookie.SameSite = SameSiteMode.Lax;
        options.ExpireTimeSpan = TimeSpan.FromDays(7);
    });
    
  • Share Data Protection Keys:
    ASP.NET Core encrypts auth cookies with data protection keys. If each site uses its own keys, Site B can't decrypt Site A's cookie. Configure both sites to use the same key store:

    services.AddDataProtection()
        // Use a shared file system folder (if both sites are on the same server)
        .PersistKeysToFileSystem(new DirectoryInfo(@"C:\SharedAuthKeys"))
        // Critical: Use the same application name for both sites
        .SetApplicationName("MyCompanySharedAuthApp");
    

2. Check ABP Zero Module-Specific Configuration

ABP Zero's modules might override default auth settings, so verify these in both sites' web modules (e.g., MyCompanyWebModule):

  • In the PreConfigureServices method, make sure authentication schemes align:

    public override void PreConfigureServices(ServiceConfigurationContext context)
    {
        PreConfigure<AuthenticationOptions>(options =>
        {
            // Ensure the default scheme matches your shared scheme from step 1
            options.DefaultAuthenticateScheme = "SharedCompanyAuthScheme";
            options.DefaultChallengeScheme = "SharedCompanyAuthScheme";
        });
    }
    
  • Double-check that any custom AbpUserClaimsPrincipalFactory or claim transformation logic is identical between sites. Mismatched claims parsing can lead to IsAuthenticated being false even if the cookie is valid.

Use your browser's dev tools (F12 → Application → Cookies) to confirm:

  • The auth cookie from Site A has the correct Domain set to your root domain (e.g., .yourdomain.com, not a.yourdomain.com).
  • The cookie's Path is / (not a subpath like /app1).
  • The cookie isn't marked as HttpOnly in a way that blocks access (ABP Zero defaults to HttpOnly, which is fine, but just confirm it's present).

4. Compare to Your ASP.NET Core 2.0 MVC Experience

Your older 2.0 apps worked because ASP.NET Core 2.x had simpler default cookie auth settings, and you likely didn't have ABP Zero's module-level overrides. ABP Zero 3.1.1 (on .NET Core 3.1) adds more opinionated auth configuration, so you need to explicitly opt into shared cookies as above.


内容的提问来源于stack exchange,提问作者ddr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 07:42:07