OIDC认证发生Correlation failed错误的场景及配置代码求助
I’ve helped several developers troubleshoot this exact issue, and based on your scenario—Chrome incognito mode, only occurring behind Azure Application Gateway, and frequency affected by cookie affinity settings—this boils down to lost request context and gateway interference with authentication cookies. Let’s break down the fixes step by step:
Core Root Causes
- Chrome incognito mode blocks third-party cookies by default. The OIDC correlation cookie (typically named
.AspNetCore.Correlation.OpenIdConnect) can be misclassified as a third-party cookie when routed through the gateway, causing the browser to discard it. Without this cookie, the authentication callback can’t validate the request, triggering the "Correlation failed" error. - When cookie affinity is disabled, requests might route to different backend instances. By default, OIDC correlation data is stored in in-memory cache, so a callback hitting a different instance won’t find the matching correlation value. Enabling affinity makes this less likely, but the gateway’s handling of cookies can still break the flow—hence the higher error frequency when affinity is on.
Targeted Solutions
1. Configure OIDC Correlation Cookie Properties
Explicitly set the correlation cookie’s attributes to ensure it’s preserved through the gateway and accepted by Chrome incognito:
services.AddAuthentication(options => { options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme; options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme; }) .AddCookie() .AddOpenIdConnect(options => { // Your existing OIDC config (authority, client ID, etc.) options.CorrelationCookie.SameSite = SameSiteMode.None; options.CorrelationCookie.SecurePolicy = CookieSecurePolicy.Always; options.CorrelationCookie.HttpOnly = true; });
SameSiteMode.Noneallows the cookie to be sent in cross-context requests (like through the gateway) while complying with modern browser standards.CookieSecurePolicy.Alwaysensures the cookie is only sent over HTTPS, which is required forSameSite=Nonein most browsers.
2. Adjust Azure Application Gateway Settings
Fix how the gateway forwards requests and handles cookies:
- Go to your Application Gateway in the Azure Portal → Rules → HTTP Settings.
- Enable Preserve client IP and Preserve host header so your backend app receives the original request context needed for OIDC validation.
- If using cookie affinity: Check that the gateway’s affinity cookie also uses
SameSite=NoneandSecureattributes (you can set this via custom response headers in the HTTP settings). If disabling affinity, proceed to the next step.
3. Use Distributed Cache for Correlation Data
When cookie affinity is off, in-memory correlation storage won’t work across backend instances. Switch to a distributed cache (like Redis) to share correlation data across all instances:
First, add the distributed cache service:
services.AddStackExchangeRedisCache(options => { options.Configuration = "your-redis-connection-string"; });
Then update your OIDC config to use it:
.AddOpenIdConnect(options => { // Existing config... options.CorrelationCacheDuration = TimeSpan.FromMinutes(10); options.UseDistributedCache(); });
This ensures any backend instance can retrieve the correlation value during the callback.
4. Enable PKCE (Recommended for Incognito Mode)
PKCE (Proof Key for Code Exchange) eliminates reliance on correlation cookies entirely, bypassing Chrome’s third-party cookie restrictions in incognito mode. It’s also a more secure modern OIDC practice:
.AddOpenIdConnect(options => { // Existing config... options.UsePkce = true; });
With PKCE, the authentication flow uses URL parameters to validate the request instead of cookies, which works seamlessly even in incognito.
Validation Steps
- Start by enabling PKCE—this will likely resolve the incognito mode issue immediately.
- Pair PKCE with the correlation cookie configuration to ensure compatibility across all browser modes and gateway setups.
- If you’re running multiple backend instances without cookie affinity, implement the distributed cache to avoid cross-instance correlation mismatches.
内容的提问来源于stack exchange,提问作者Sat Thiru

