【发布时间】:2021-04-18 14:21:20
【问题描述】:
所以我正在尝试使用 Azure AD B2C 保护 Web API,但是当我尝试使用使用“运行用户流”获得的令牌访问端点时,我收到以下异常:
System.UnauthorizedAccessException:IDW10201:既不是作用域也不是角色 在不记名令牌中找到声明。
我的代码:
我创建了一个新的 ASP.NET Core 应用程序并使用对话框自动添加身份验证。
代码中一些有趣的点:
我尝试将以下内容添加到 appsettings.json 文件中,但没有帮助:
"AllowWebApiToBeAuthorizedByACL": true
我尝试从控制器中删除它,但没有帮助:
// The Web API will only accept tokens 1) for users, and 2) having the "access_as_user" scope for this API
static readonly string[] scopeRequiredByApi = new string[] { "access_as_user" };
HttpContext.VerifyUserHasAnyAcceptedScope(scopeRequiredByApi);
在 ConfigureServices 我有以下代码:
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
.AddMicrosoftIdentityWebApi(Configuration.GetSection("AzureAdB2C"));
Azure 门户:
-
我为 Azure AD B2C 创建了一个新租户
-
我注册了一个应用程序
- API 权限
这里我玩了很多,这些是我现在启用的权限:
- 创建用户流
然后,当我运行用户流时,我得到了:
使用的链接:
https://xxxxxxxxxxx001.b2clogin.com/xxxxxxxxx001.onmicrosoft.com/oauth2/v2.0/authorize?
p=B2C_1_user_flow_test_signinsignup
&client_id=xxxxxxxxxxxx
&nonce=defaultNonce
&redirect_uri=https%3A%2F%2Fjwt.ms
&scope=openid
&response_type=id_token
&prompt=登录
我对 azure 完全陌生,在研究了整个互联网之后,我无法弄清楚这里的问题是什么,以及为什么 scp 不在我从 azure 门户中提供的链接运行用户流时获得的令牌中。
对于我缺少设置或设置错误的内容,我非常感谢。
【问题讨论】:
-
您调用的是受 Azure 保护的 api 还是 MS graph api?
-
我正在使用 Azure 门户中的“运行用户流”功能。基本上它只提供一个链接,如下所示:mytenant.b2clogin.com/mytenant.onmicrosoft.com/oauth2/v2.0/…
标签: c# azure asp.net-core azure-ad-b2c