I have a single tenant scenario in Azure Active Directory where an API1 needs to call another API2 using authentication, and where the API1 was called from a SPA.
Would it be correct to just pass on the user's JWT received in API1 from the SPA to call API2 for authentication?
new WindowsAzureActiveDirectoryBearerAuthenticationOptions
{
TokenValidationParameters = new TokenValidationParameters() {
SaveSigninToken = true,
...
like in: https://github.com/Azure-Samples/active-directory-dotnet-webapi-onbehalfof
All APIs are implemented with ASP.NET Web API and the SPA using Active Directory Authentication Library (ADAL) for JavaScript.
