We have a website and a public api, both of which are defined as Clients in Identity Server:
public static IEnumerable<Client> GetClients()
{
return new List<Client>
{
// resource owner password grant client
new Client
{
ClientId = "API_RO",
AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,
ClientSecrets =
{
new Secret("secret".Sha256())
},
AllowedScopes = { "WEB_API" },
IncludeJwtId = true,
AlwaysIncludeUserClaimsInIdToken = true,
AlwaysSendClientClaims = true
},
// OpenID Connect implicit flow client (MVC)
new Client
{
ClientId = "PUBLIC_SPA_APPLICATION",
AllowedGrantTypes = GrantTypes.Implicit,
AllowAccessTokensViaBrowser = true,
AllowedScopes = new List<string>
{
IdentityServerConstants.StandardScopes.OpenId,
IdentityServerConstants.StandardScopes.Profile,
"WEB_API",
},
IncludeJwtId = true,
AlwaysIncludeUserClaimsInIdToken = true,
}
}
}
And in the web service we are authenticating against the token that is sent
public void Configure(IApplicationBuilder app, IHostingEnvironment env, ILoggerFactory loggerFactory, IServiceDiscovery serviceDiscovery)
{
app.UseIdentityServerAuthentication(new IdentityServerAuthenticationOptions
{
Authority = $"{serviceInformation.Prefix}{serviceInformation.IpAddress}:{serviceInformation.Port}",
RequireHttpsMetadata = false,
ApiName = "PUBLIC_SPA_APPLICATION", //"API_RO",<= PROBLEM HERE
SaveToken = false
});
}
The problem that I have is that the ApiName parameter only allows for one client to be set. I need to find a way for it to work for both clients that have come via the website and ones that have come via the API.
Currently I am getting the following error:
Bearer was not authenticated. Failure message: IDX10214: Audience validation failed. Audiences: 'PUBLIC_SPA_APPLICATION'. Did not match: validationParameters.ValidAudience: 'API_RO' or validationParameters.ValidAudiences: 'null'.