The ASP.Net team has been somewhat hard headed about this for quite a while. They just didn’t seem to grasp how this could be a problem. Glad they have finally come around.
Just went through this with my app. Being new to asp.net core and trying to wrap your head around the authentication spaghetti monster well enough to get what you want and be comfortable answering security questionnaires about your product.. It's bonkers.