AdalClaimChallengeException
抛出,说明需要用户干预:
AADSTS50079:用户需要使用多因素身份验证
异常的声明值如下所示:
{
"access_token": {
"capolids": {
"essential": true,
"values": ["<GUID>"]
}
}
}
这个
Azure AD documentation
表明
claims质询位于WWW Authenticate报头内,可以对其进行解析以提取下一个请求的claims参数。
一旦附加到新请求中,azuread就知道要评估条件访问策略
当用户登录时,应用程序现在符合条件访问策略
和
在我们的webapi1中,我们捕捉错误error=interaction\u required,并将claims质询发回桌面应用程序。此时,桌面应用程序可以进行新的acquireToken()调用,并
. 此新请求要求用户执行多因素身份验证,然后将此新令牌发送回Web API 1并完成代表流。
我不知道如何在MVC应用程序中做到这一点。中间件组件都设置好发出请求,我可以在
OnAuthenticationFailed
services.AddOpenIdConnect(opts => {
Configuration.GetSection("Authentication")
.Bind(opts);
opts.ClientSecret = aadClientSecret.Value;
opts.Events = new OpenIdConnectEvents {
OnAuthorizationCodeReceived = async ctx => {
HttpRequest request = ctx.HttpContext.Request;
//We need to also specify the redirect URL used
string currentUri = UriHelper
.BuildAbsolute(request.Scheme, request.Host, request.PathBase, request.Path);
//Credentials for app itself
var credential = new ClientCredential(ctx.Options.ClientId, ctx.Options.ClientSecret);
//Construct token cache
ITokenCacheFactory cacheFactory =
ctx.HttpContext.RequestServices.GetRequiredService<ITokenCacheFactory>();
TokenCache cache = cacheFactory.CreateForUser(ctx.Principal);
var authContext = new AuthenticationContext(ctx.Options.Authority, cache);
//Get token for Microsoft Graph API using the authorization code
string resource = "https://graph.microsoft.com";
AuthenticationResult result =
await authContext.AcquireTokenByAuthorizationCodeAsync(
ctx.ProtocolMessage.Code, new Uri(currentUri), credential, resource);
//Tell the OIDC middleware we got the tokens, it doesn't need to do anything
ctx.HandleCodeRedemption(result.AccessToken, result.IdToken);
},
OnAuthenticationFailed = async ctx => {
var adalException = ctx.Exception as AdalClaimChallengeException;
if (adalException != null) {
HttpRequest request = ctx.HttpContext.Request;
var claims = adalException.Claims;
string currentUri = UriHelper.BuildAbsolute(request.Scheme, request.Host, request.PathBase, request.Path);
//Credentials for app itself
var credential = new ClientCredential(ctx.Options.ClientId, ctx.Options.ClientSecret);
// there is no user, how do I get their cache?
var cache = new TokenCache();
var authContext = new AuthenticationContext(ctx.Options.Authority, cache);
var result = await authContext.AcquireTokenAsync("https://graph.microsoft.com", credential);
// now what?
}
}