代码之家  ›  专栏  ›  技术社区  ›  Dylan

ASP.NET核心如何在请求额外资源时处理AdalClaimChallengeException

  •  1
  • Dylan  · 技术社区  · 8 年前

    AdalClaimChallengeException 抛出,说明需要用户干预:

    AADSTS50079:用户需要使用多因素身份验证

    异常的声明值如下所示:

    {
      "access_token": {
        "capolids": {
          "essential": true,
          "values": ["<GUID>"]
        }
      }
    }
    

    这个 Azure AD documentation 表明

    claims质询位于WWW Authenticate报头内,可以对其进行解析以提取下一个请求的claims参数。 一旦附加到新请求中,azuread就知道要评估条件访问策略 当用户登录时,应用程序现在符合条件访问策略

    和

    在我们的webapi1中,我们捕捉错误error=interaction\u required,并将claims质询发回桌面应用程序。此时,桌面应用程序可以进行新的acquireToken()调用,并 . 此新请求要求用户执行多因素身份验证,然后将此新令牌发送回Web API 1并完成代表流。

    我不知道如何在MVC应用程序中做到这一点。中间件组件都设置好发出请求,我可以在 OnAuthenticationFailed

    services.AddOpenIdConnect(opts => {
        Configuration.GetSection("Authentication")
        .Bind(opts);
    
        opts.ClientSecret = aadClientSecret.Value;
    
        opts.Events = new OpenIdConnectEvents {
            OnAuthorizationCodeReceived = async ctx => {
                HttpRequest request = ctx.HttpContext.Request;
    
                //We need to also specify the redirect URL used
                string currentUri = UriHelper
                    .BuildAbsolute(request.Scheme, request.Host, request.PathBase, request.Path);
    
                //Credentials for app itself
                var credential = new ClientCredential(ctx.Options.ClientId, ctx.Options.ClientSecret);
    
                //Construct token cache
                ITokenCacheFactory cacheFactory = 
                    ctx.HttpContext.RequestServices.GetRequiredService<ITokenCacheFactory>();
                TokenCache cache = cacheFactory.CreateForUser(ctx.Principal);
    
                var authContext = new AuthenticationContext(ctx.Options.Authority, cache);
    
                //Get token for Microsoft Graph API using the authorization code
                string resource = "https://graph.microsoft.com";
                AuthenticationResult result = 
                    await authContext.AcquireTokenByAuthorizationCodeAsync(
                        ctx.ProtocolMessage.Code, new Uri(currentUri), credential, resource);
    
                //Tell the OIDC middleware we got the tokens, it doesn't need to do anything
                ctx.HandleCodeRedemption(result.AccessToken, result.IdToken);
            },
            OnAuthenticationFailed = async ctx => {
                var adalException = ctx.Exception as AdalClaimChallengeException;
                if (adalException != null) {
                    HttpRequest request = ctx.HttpContext.Request;
                    var claims = adalException.Claims;
                    string currentUri = UriHelper.BuildAbsolute(request.Scheme, request.Host, request.PathBase, request.Path);
                    //Credentials for app itself
                    var credential = new ClientCredential(ctx.Options.ClientId, ctx.Options.ClientSecret);
    
                    // there is no user, how do I get their cache?
                    var cache = new TokenCache();
    
                    var authContext = new AuthenticationContext(ctx.Options.Authority, cache);
                    var result = await authContext.AcquireTokenAsync("https://graph.microsoft.com", credential);
                    // now what?
                }
            }
    
    0 回复  |  直到 8 年前