【问题标题】:.NET Core WebApi + Angular Authentication & Authorization via applications in Microsoft Azure.NET Core WebApi + Angular 身份验证和授权通过 Microsoft Azure 中的应用程序
【发布时间】:2021-10-21 19:18:32
【问题描述】:

我们在 Angular 上有 2 个 Web 应用程序(FE_1、FE_2),在 .NET Core 上有 3 个 API 应用程序(见图) 需要从一个站点一次登录并在两个站点之间工作,无需任何额外的授权过程 我的意思是,当我们登录到站点 1 并接收令牌 #1 时,我希望此令牌也可以与 API_2 一起使用,反之亦然,当我们登录到站点 2 并接收令牌 #2 时,我想使用此令牌来工作以及 API_1

所以我的问题是如何在 Azure 中正确配置应用程序并根据所描述的架构在内部配置它们?

【问题讨论】:

标签: c# .net angular azure


【解决方案1】:

谢谢Manish。发布您的建议作为帮助其他社区成员的答案。

从提供的 BE 代码架构中添加有效受众列表,如下图所示,使其变为 true

下面是示例代码,您可以在其中检查有效的受众代码。

services.AddAuthentication(cfg =>
{
    cfg.DefaultAuthenticateScheme = JwtBearerDefaults.AuthenticationScheme;
    cfg.DefaultChallengeScheme = JwtBearerDefaults.AuthenticationScheme;
})
.AddJwtBearer(opt =>
{
    opt.Authority = "https://login.microsoftonline.com/common";
    opt.Audience = "api://A134d6c8-8078-2924-9e90-98cef862eb9a"; // Set this to the App ID URL for the web API, which you created when you registered the web API with Azure AD.

    opt.TokenValidationParameters = new TokenValidationParameters
    {
        ValidateIssuer = true, 
        ValidateAudience = true, 
        ValidAudiences = new List<String>
        {
            // you could add a list of valid audiences
            "A134d6c8-8078-2924-9e90-98cef862eb9a"
        }, 
        ValidIssuers = new List<string>
        {
            // Add tenant id after https://sts.windows.net/
            "https://sts.windows.net/{YourTenantId}"
        }
    };
    opt.Events = new JwtBearerEvents()
    {
        OnAuthenticationFailed = AuthenticationFailed
    };
});

如需完整信息,请查看SO。

【讨论】:

    猜你喜欢
    • 2020-08-06
    • 1970-01-01
    • 1970-01-01
    • 2022-06-10
    • 2018-07-13
    • 2017-06-04
    • 1970-01-01
    • 1970-01-01
    • 2021-12-18
    相关资源
    最近更新 更多