ASP.Net Core Secure Cookie behind Azure Application Gateway

Viewed 494

I have an ASP.Net Core 3.1 application that used to be hosted on an Azure WebApp with SSL enabled. Now I need to move the app to a Kubernetes Cluster (managed AKS). For ingress, an Azure Application Gateway is used, which also handles and terminates the SSL connection. As a result, all traffic is routed from the Application Gateway to the app via HTTP (without SSL) and ASP doesn't set the Secure attribute (which is required in Chrome because of SameSite=None) on the cookie required for authentication. Following the Microsoft Docs regarding hosting ASP behind proxies or load balancers, I already included

app.UseForwardedHeaders(new ForwardedHeadersOptions {
    ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedHost | ForwardedHeaders.XForwardedProto
});

Still, the login fails on chrome and I can see in the browser tools that the cookie does not have the secure attribute. I use the following cookie options:

services.Configure<CookiePolicyOptions>(options => {
    options.CheckConsentNeeded = context => true;
    options.HttpOnly = HttpOnlyPolicy.Always;
    options.Secure = CookieSecurePolicy.Always;
    options.MinimumSameSitePolicy = SameSiteMode.None;
});
0 Answers
Related