Is it possible to access the clientId from an authToken (RequestContext) in WebAPI 2

Viewed 2428

I have implemented Oauth with my WebAPI 2 application and there are several applications access the API. Once authenticated, after making a request whilst sending across the auth token, I can access the user as follows:

var currentUser = RequestContext.Principal;

When logging in, the clientId was set as follows:

context.OwinContext.Set<AppClient>("oauth:client", client);

Is there a way to access that client Id? I want to restrict certain actions / controllers to certain clients. Is there a way to do this?

I have tried getting the client as follows:

var client = Request.GetOwinContext().Get<string>("oauth:client");

but this is not working.

2 Answers

You can use AuthenticationProperties instead. Same as answered, in GrantResourceOwnerCredentials just implement next stuff while ticket issuing:

var props = new AuthenticationProperties(new Dictionary<string, string>
{
    {
        "client_id", clientId
    },
});

var ticket = new AuthenticationTicket(identity, props);
context.Validated(ticket);    

Then, you'll be able to get value via context.Ticket.Properties.Dictionary["client_id"];

Related