authenticate with identity server for more than one api

Viewed 523

We have a website and a public api, both of which are defined as Clients in Identity Server:

public static IEnumerable<Client> GetClients()
{
    return new List<Client>
    {
        // resource owner password grant client
        new Client
        {
            ClientId = "API_RO",
            AllowedGrantTypes = GrantTypes.ResourceOwnerPassword,

            ClientSecrets =
            {
                new Secret("secret".Sha256())
            },
            AllowedScopes = { "WEB_API" },
            IncludeJwtId = true,
            AlwaysIncludeUserClaimsInIdToken = true,
            AlwaysSendClientClaims = true                    
        },
        // OpenID Connect implicit flow client (MVC)
        new Client
        {
            ClientId = "PUBLIC_SPA_APPLICATION",
            AllowedGrantTypes = GrantTypes.Implicit,
            AllowAccessTokensViaBrowser = true,

            AllowedScopes = new List<string>
            {
                IdentityServerConstants.StandardScopes.OpenId,
                IdentityServerConstants.StandardScopes.Profile,
                "WEB_API",
            },

            IncludeJwtId = true,
            AlwaysIncludeUserClaimsInIdToken = true,
        }
    }
}

And in the web service we are authenticating against the token that is sent

public void Configure(IApplicationBuilder app, IHostingEnvironment env, ILoggerFactory loggerFactory, IServiceDiscovery serviceDiscovery)
{
    app.UseIdentityServerAuthentication(new IdentityServerAuthenticationOptions
    {
        Authority = $"{serviceInformation.Prefix}{serviceInformation.IpAddress}:{serviceInformation.Port}",
        RequireHttpsMetadata = false,                
        ApiName = "PUBLIC_SPA_APPLICATION", //"API_RO",<= PROBLEM HERE
        SaveToken = false
    });
}

The problem that I have is that the ApiName parameter only allows for one client to be set. I need to find a way for it to work for both clients that have come via the website and ones that have come via the API.

Currently I am getting the following error:

Bearer was not authenticated. Failure message: IDX10214: Audience validation failed. Audiences: 'PUBLIC_SPA_APPLICATION'. Did not match: validationParameters.ValidAudience: 'API_RO' or validationParameters.ValidAudiences: 'null'.

0 Answers
Related