I have an ASP.Net Core 3.1 application that used to be hosted on an Azure WebApp with SSL enabled. Now I need to move the app to a Kubernetes Cluster (managed AKS). For ingress, an Azure Application Gateway is used, which also handles and terminates the SSL connection.
As a result, all traffic is routed from the Application Gateway to the app via HTTP (without SSL) and ASP doesn't set the Secure attribute (which is required in Chrome because of SameSite=None) on the cookie required for authentication.
Following the Microsoft Docs regarding hosting ASP behind proxies or load balancers, I already included
app.UseForwardedHeaders(new ForwardedHeadersOptions {
ForwardedHeaders = ForwardedHeaders.XForwardedFor | ForwardedHeaders.XForwardedHost | ForwardedHeaders.XForwardedProto
});
Still, the login fails on chrome and I can see in the browser tools that the cookie does not have the secure attribute. I use the following cookie options:
services.Configure<CookiePolicyOptions>(options => {
options.CheckConsentNeeded = context => true;
options.HttpOnly = HttpOnlyPolicy.Always;
options.Secure = CookieSecurePolicy.Always;
options.MinimumSameSitePolicy = SameSiteMode.None;
});