【问题标题】:Sharing Cookies Between Two ASP.NET Core Applications在两个 ASP.NET Core 应用程序之间共享 Cookie
【发布时间】:2018-08-25 23:42:54
【问题描述】:

我在两个单独的 ASP.NET Core 项目中使用WsFederation。

每个项目在Startup.cs中都有以下内容

services.AddAuthentication(sharedOptions =>
{
    sharedOptions.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    sharedOptions.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    sharedOptions.DefaultChallengeScheme = WsFederationDefaults.AuthenticationScheme;
})
.AddWsFederation(options =>
{
    options.Wtrealm = Configuration["Wtrealm"];
    options.MetadataAddress = "http://example.com/metadata.xml";
    options.SkipUnrecognizedRequests = true;
    options.RequireHttpsMetadata = false;
    options.UseTokenLifetime = false;
})
.AddCookie(options =>
{
    options.Cookie.Name = "MySharedCookie";
    options.Cookie.Path = "/";
    options.Cookie.Domain = ".dev.example.com";
});

我在浏览器中加载项目 #1 并获得我的 cookie:

然后我导航到同一子域上的项目#2。但是,项目 #2 无法识别 MySharedCookie 并重新进行身份验证。我得到一个名称相同但值不同的新 cookie:

我在 ASP.NET Core 中尝试做的事情是否可行?在 ASP.NET Core 中有没有办法可以将项目 #1 的 cookie 与项目 #2 共享?

【问题讨论】:

  • 也许this 可以帮忙?
  • 他们还必须共享他们的数据保护密钥。

标签: c# asp.net-core asp.net-core-mvc asp.net-core-2.0


【解决方案1】:

这记录在Sharing cookies among apps with ASP.NET and ASP.NET Core。还有一个Cookie Sharing App Sample 可用。

为了共享 cookie,您在每个应用程序中创建一个 DataProtectionProvider,并在应用程序之间使用一组公共/共享密钥。

.AddCookie(options =>
{
    options.Cookie.Name = ".SharedCookie";
    options.Cookie.Domain = "example.com";
    options.DataProtectionProvider =
        DataProtectionProvider.Create(new DirectoryInfo("path-tokeys"));
});

【讨论】:

猜你喜欢
  • 1970-01-01
  • 2018-12-20
  • 1970-01-01
  • 1970-01-01
  • 2019-01-22
  • 2018-12-24
  • 2011-02-26
  • 2018-04-19
  • 1970-01-01
相关资源
最近更新 更多