I have developed the Rest APIs using .Net Core and my API is consumed by two sources, one from the UI and another from the services.
For Authorizing UI, i have used JWToken approach with claims, where as for Services I have used Role based Integrated security authorization.
i.e., for UI, i need to provide [Authorize(Policy="XYZ")] where as for Services, I need to provide [Authorize(Role="ABC")]
Most of my apis are either used by UI or services dedicatedly, but there are few APIs which can be used by both UI and Services, but facing, hence for such APIs, i need to provide a condition like either Role or Policy matches,
Eg., Authorize[Role="ABC", Policy="XYZ"] , but this statement expects both Role and policy to be available with AND Condition, but i need to solution to implement the same with kind of OR condition. Please help me if anyone has encountered this type of scenario.
FYI, I have tried using Custom Attributes, but it is not working out, because I have custom attributes independently created for Roles (Using AuthorizeAttribute) and for Policies (Using TypeFilterAttribute and IAsyncAuthorizationFilter), but again I am not able to combine the same with OR condition