【问题标题】:Azure B2C Returns Error Bearer error="invalid_token", error_description="The signature is invalidAzure B2C 返回错误持有者 error="invalid_token", error_description="签名无效
【发布时间】:2021-10-01 22:00:14
【问题描述】:

我在 Azure B2C 上设置了一个应用程序和 api。我尝试了不同的变体,但最终出现错误 Bearer error="invalid_token", error_description="The signature is invalid when I call an endpoint using Postman."

我在 Azure 上的设置是 Azure App Registration 我在 .Net Core 的启动是: s

services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
                .AddJwtBearer(opt =>
                {
                    opt.Audience = Configuration["AzureAd:ResourceId"];
                    opt.Authority = $"{Configuration["AzureAd:Instance"]}{Configuration["AzureAd:TenantId"]}";
                    opt.TokenValidationParameters = new TokenValidationParameters
                    {
                        ValidateIssuer = true,
                        ValidIssuer = "https://https://CareHomeBookingTest.onmicrosoft.com/oauth2/default"
                    };
                });

我正在尝试调用受 Authorize 属性保护的端点

[Authorize]        
 [Route("Secure")]
 [HttpGet("Residents")]
 [Produces("application/json")]

public async Task<IActionResult> GetAllResidents()
 {
     return Ok(await _mediator.Send(new ResidentGetAllQuery()));
 }

在 Postman 上,我可以调用并获取令牌:

Postman values

返回的jwt令牌是

{
  "iss": "https://carehomebookingtest.b2clogin.com/d452b############-e150f022535e/v2.0/",
  "exp": 1633036666,
  "nbf": 1633022266,
  "aud": "e72a######################",
  "sub": "7ac#######################",
  "given_name": "john",
  "family_name": "smith",
  "tfp": "B2C_1_SignUpIn",
  "scp": "admin",
  "azp": "e72##################",
  "ver": "1.0",
  "iat": 1633022266
}

但是当我调用上面提到的端点时,我得到了错误。

enter image description here

【问题讨论】:

  • 您的 Postman 链接已损坏。
  • 您正在使用 AAD 保护您的 API,但您的令牌来自 AAD B2C,因此它永远不会起作用。 B2C api 示例:docs.microsoft.com/en-us/azure/active-directory-b2c/…
  • @JasSuri-MSFT 我已根据您提供的示例添加了启动值,现在我收到错误“IDX20803:无法从:'System.String' 获取配置。”
  • appsettings.json 文件中的新值是:"AzureAdB2C": { "Instance": "login.microsoftonline.com", "ClientId": "010e########### #############", "域": "CareHomeBookingTest.onmicrosoft.com", "SignedOutCallbackPath": "/signout/B2C_1_susi_reset_v2", "SignUpSignInPolicyId": "B2C_1_SignUpIn" //"CallbackPath ": "/signin/B2C_1_sign_up_in" // 默认为 /signin-oidc }
  • 配置服务值如下。不确定是否需要添加 NameClaimType。 services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme) .AddMicrosoftIdentityWebApi(options => { Configuration.Bind("AzureAdB2C", options); options.TokenValidationParameters.NameClaimType = "test"; }, options => { Configuration.Bind("AzureAdB2C",选项);});

标签: .net azure azure-ad-b2c


【解决方案1】:

感谢 Jas Suri - MSFT 发布您的建议作为帮助其他社区成员的答案。

因此,在您如下更改appsettings.json 中的实例名称后,基于此MS DOC 希望可以解决您的问题。

"AzureAdB2C": { "Instance": "https://<your-tenant-name>.b2clogin.com", 
"ClientId": "<web-app-application-id>", 
"Domain": "<your-b2c-domain>", 
"SignedOutCallbackPath": "/signout/<your-sign-up-in-policy>", 
"SignUpSignInPolicyId": "<your-sign-up-in-policy>" }

有关详细信息,请参阅此 Microsoft 文档:Configure authentication in a sample web app that calls a web API by using Azure AD B2C.

【讨论】:

    猜你喜欢
    • 2020-12-24
    • 2018-08-03
    • 2020-10-08
    • 2020-06-03
    • 2021-07-26
    • 2021-08-19
    • 2021-09-06
    • 2021-02-06
    • 2020-06-04
    相关资源
    最近更新 更多