How do I set cookie to be secure .NET Core?

Viewed 833

I've run into problems using Identity Server 4. It's the common problem that requires SameSite=None and secure cookies. While I managed to set SameSite to None, I didn't set cookies to be secure.

I tried searching online but couldn't find any complete solution. I will need information where to use that part of code too, since I'm not experienced.

I am using ASP.NET Core 3.1.

Thanks

1 Answers

You can set cookie settings like this

services.AddIdentityServer()
.AddInMemoryClients(Clients.Get())
.AddInMemoryIdentityResources(Resources.GetIdentityResources())
.AddInMemoryApiResources(Resources.GetApiResources())
.AddDeveloperSigningCredential()
.AddTestUsers(TestUsers.Users);

services.AddAuthentication("MyCookie")
    .AddCookie("MyCookie", options =>
    {
        options.ExpireTimeSpan = ...;
    });

for more information read Cookie authentication.

Related