【问题标题】:Setting SameSite=None and Secure in ASP.NET在 ASP.NET 中设置 SameSite=None 和 Secure
【发布时间】:2020-02-05 07:09:51
【问题描述】:

了解为防止跨站点伪造而强制执行的 SameSite 更改。 来源:https://blog.chromium.org/2019/10/developers-get-ready-for-new.html

我正在尝试将其值设置为“无”并使用 Secure 作为广告。

我目前的web.config设置如下:

<system.web>
    <sessionState cookieless="UseCookies" 
       timeout="20" 
       cookieSameSite="None" 
       xdt:Transform="Replace" 
       xdt:Locator="Match(cookieless)"/>
  </system.web>

文档来源: https://docs.microsoft.com/en-us/dotnet/api/system.web.configuration.sessionstatesection.cookiesamesite?view=netframework-4.8#System_Web_Configuration_SessionStateSection_CookieSameSite

但我仍然收到以下错误:

A cookie associated with a resource at `mywebsite.net` was set with `SameSite=None` but without `Secure`. A future release of Chrome will only deliver cookies marked `SameSite=None` if they are also marked `Secure`.

如何在上面的 web.config 文件中指定secure 属性?任何线索将不胜感激。

【问题讨论】:

    标签: c# asp.net cookies web-config samesite


    【解决方案1】:

    根据 Microsoft 的此链接,sessionState 没有该属性,因此它回退到 httpCookies 部分。 https://docs.microsoft.com/en-us/aspnet/samesite/system-web-samesite 希望对您有所帮助。

    【讨论】:

    • 所以,我们应该回退并在 web.config 中使用 &lt;httpCookies requireSSL="true"&gt; 之类的东西?
    • YES 是该评论问题的答案。
    【解决方案2】:

    您也可以在每次创建 cookie 时设置它

    using SameSiteMode = Microsoft.AspNetCore.Http.SameSiteMode;
    ....
    context.HttpContext.Response.Cookies.Append(cookie.Key, cookie.Value,
     new CookieOptions { SameSite = SameSiteMode.None,Secure = true });
    

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2020-05-22
      • 2020-12-26
      • 2020-09-01
      • 1970-01-01
      • 1970-01-01
      • 2020-11-01
      相关资源
      最近更新 更多