You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OIDC认证发生Correlation failed错误的场景及配置代码求助

Fixing "Correlation failed." Error in OIDC Authentication with Azure Application Gateway

I’ve helped several developers troubleshoot this exact issue, and based on your scenario—Chrome incognito mode, only occurring behind Azure Application Gateway, and frequency affected by cookie affinity settings—this boils down to lost request context and gateway interference with authentication cookies. Let’s break down the fixes step by step:

Core Root Causes

  • Chrome incognito mode blocks third-party cookies by default. The OIDC correlation cookie (typically named .AspNetCore.Correlation.OpenIdConnect) can be misclassified as a third-party cookie when routed through the gateway, causing the browser to discard it. Without this cookie, the authentication callback can’t validate the request, triggering the "Correlation failed" error.
  • When cookie affinity is disabled, requests might route to different backend instances. By default, OIDC correlation data is stored in in-memory cache, so a callback hitting a different instance won’t find the matching correlation value. Enabling affinity makes this less likely, but the gateway’s handling of cookies can still break the flow—hence the higher error frequency when affinity is on.

Targeted Solutions

Explicitly set the correlation cookie’s attributes to ensure it’s preserved through the gateway and accepted by Chrome incognito:

services.AddAuthentication(options =>
{
    options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
})
.AddCookie()
.AddOpenIdConnect(options =>
{
    // Your existing OIDC config (authority, client ID, etc.)
    options.CorrelationCookie.SameSite = SameSiteMode.None;
    options.CorrelationCookie.SecurePolicy = CookieSecurePolicy.Always;
    options.CorrelationCookie.HttpOnly = true;
});
  • SameSiteMode.None allows the cookie to be sent in cross-context requests (like through the gateway) while complying with modern browser standards.
  • CookieSecurePolicy.Always ensures the cookie is only sent over HTTPS, which is required for SameSite=None in most browsers.

2. Adjust Azure Application Gateway Settings

Fix how the gateway forwards requests and handles cookies:

  • Go to your Application Gateway in the Azure Portal → Rules → HTTP Settings.
  • Enable Preserve client IP and Preserve host header so your backend app receives the original request context needed for OIDC validation.
  • If using cookie affinity: Check that the gateway’s affinity cookie also uses SameSite=None and Secure attributes (you can set this via custom response headers in the HTTP settings). If disabling affinity, proceed to the next step.

3. Use Distributed Cache for Correlation Data

When cookie affinity is off, in-memory correlation storage won’t work across backend instances. Switch to a distributed cache (like Redis) to share correlation data across all instances:
First, add the distributed cache service:

services.AddStackExchangeRedisCache(options =>
{
    options.Configuration = "your-redis-connection-string";
});

Then update your OIDC config to use it:

.AddOpenIdConnect(options =>
{
    // Existing config...
    options.CorrelationCacheDuration = TimeSpan.FromMinutes(10);
    options.UseDistributedCache();
});

This ensures any backend instance can retrieve the correlation value during the callback.

PKCE (Proof Key for Code Exchange) eliminates reliance on correlation cookies entirely, bypassing Chrome’s third-party cookie restrictions in incognito mode. It’s also a more secure modern OIDC practice:

.AddOpenIdConnect(options =>
{
    // Existing config...
    options.UsePkce = true;
});

With PKCE, the authentication flow uses URL parameters to validate the request instead of cookies, which works seamlessly even in incognito.

Validation Steps

  1. Start by enabling PKCE—this will likely resolve the incognito mode issue immediately.
  2. Pair PKCE with the correlation cookie configuration to ensure compatibility across all browser modes and gateway setups.
  3. If you’re running multiple backend instances without cookie affinity, implement the distributed cache to avoid cross-instance correlation mismatches.

内容的提问来源于stack exchange,提问作者Sat Thiru

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:14:14