【问题标题】:Retrieve access token from Third party OAuth providers从第三方 OAuth 提供程序检索访问令牌
【发布时间】:2021-07-05 22:22:48
【问题描述】:

我正在尝试从 WCF 服务调用 OAuth2.0 api 以检索 accessToken。 我设法使用下面的代码调用了 Azure 中的 OAuth2.0 API:

            // Create confidential client application
        IConfidentialClientApplication app = ConfidentialClientApplicationBuilder.Create(oAuthAuthenticationConfig.ClientId)
                                                        .WithClientSecret(oAuthAuthenticationConfig.ClientSecret)
                                                        .WithAuthority(new Uri(oAuthAuthenticationConfig.Authority))
                                                        .Build();

    string[] scopes = new string[] { $"{oAuthAuthenticationConfig.ApiUrl}" };

  result = await app.AcquireTokenForClient(scopes)
                              .ExecuteAsync();

不,我不确定如何将其用于 Google 中的 OAuth2.0 API。 ConfidentialClientApplicationBuilder.Create(CliendId) 作为参数的客户端 ID 必须是有效的 GUID,而我从 Google OAuth 应用程序生成的客户端 ID 类似于

 const string clientID = "879017285009-4igdmblu7i6b7djetijvjhc5p1h7v2ul.apps.googleusercontent.com"; 

我什至可以将 nuget Microsoft.Identity.Client 中定义的 ConfidentialClientApplicationBuilder 用于 Google/第三方 OAuth2.0 提供程序吗?如果不是,我的其他选择是什么?

【问题讨论】:

    标签: azure oauth-2.0 google-oauth


    【解决方案1】:

    Google.Apis.Auth 包可让您以服务帐户身份进行身份验证,并且还负责在访问令牌过期之前对其进行刷新。请参阅Authenticating as a service account 了解一些使用示例。

    在 Azure 上使用 ...WithClientSecret(...) 的等效方法是使用 Google Cloud 上的服务帐户密钥进行身份验证。但是,如果您的服务已经拥有 Azure 凭据,也可以选择使用 Workload identity federation 将 Azure 访问令牌与 Google 访问令牌交换,从而使您不必管理另一个密钥。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2015-05-28
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      • 2019-10-09
      • 2015-09-29
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多