【问题标题】:.NET Core WebApi + Angular Authentication & Authorization via applications in Microsoft Azure.NET Core WebApi + Angular 身份验证和授权通过 Microsoft Azure 中的应用程序
【发布时间】:2021-10-21 19:18:32
【问题描述】:
我们在 Angular 上有 2 个 Web 应用程序(FE_1、FE_2),在 .NET Core 上有 3 个 API 应用程序(见图)
需要从一个站点一次登录并在两个站点之间工作,无需任何额外的授权过程
我的意思是,当我们登录到站点 1 并接收令牌 #1 时,我希望此令牌也可以与 API_2 一起使用,反之亦然,当我们登录到站点 2 并接收令牌 #2 时,我想使用此令牌来工作以及 API_1
所以我的问题是如何在 Azure 中正确配置应用程序并根据所描述的架构在内部配置它们?
【问题讨论】:
标签:
c#
.net
angular
azure
【解决方案1】:
谢谢Manish。发布您的建议作为帮助其他社区成员的答案。
从提供的 BE 代码架构中添加有效受众列表,如下图所示,使其变为 true
下面是示例代码,您可以在其中检查有效的受众代码。
services.AddAuthentication(cfg =>
{
cfg.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
cfg.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(opt =>
{
opt.Authority = "https://login.microsoftonline.com/common";
opt.Audience = "api://A134d6c8-8078-2924-9e90-98cef862eb9a"; // Set this to the App ID URL for the web API, which you created when you registered the web API with Azure AD.
opt.TokenValidationParameters = new TokenValidationParameters
{
ValidateIssuer = true,
ValidateAudience = true,
ValidAudiences = new List<String>
{
// you could add a list of valid audiences
"A134d6c8-8078-2924-9e90-98cef862eb9a"
},
ValidIssuers = new List<string>
{
// Add tenant id after https://sts.windows.net/
"https://sts.windows.net/{YourTenantId}"
}
};
opt.Events = new JwtBearerEvents()
{
OnAuthenticationFailed = AuthenticationFailed
};
});
如需完整信息,请查看SO。