MacOS development in ASP.NET Core 3.1 on Rider: Windows Authentication

Viewed 855

I recently switched from a Windows machine with Visual Studio to a MacBook with Rider. I have a .NET Core 3.1 project that I upgraded from .NET Framework 4.7.2, and I am trying to configure Windows Authentication for it.

My MacBook is connected to a company domain via Enterprise Connect, and I have active kerboros tickets. AKA, I am able to access company resources that use Windows Authentication or otherwise pull my domain credentials. For example, I can login to the published version of my project which runs on IIS and .NET Framework 4.7.2.

However, I am not able to use Windows Authentication when I run the .NET Core 3.1 version locally. I have made the following changes to my project:

In StartUp.cs, added the following to ConfigureServices:

services.AddAuthentication(NegotiateDefaults.AuthenticationScheme).AddNegotiate();
services.AddAuthorization(options =>
{
    options.AddPolicy(nameof(Policy.AuthorizedUser), 
        policy => policy.Requirements.Add(new AuthorizedUserRequirement()));
});

services.AddSingleton<IAuthorizationHandler, AuthorizedUserHandler>();

In StartUp.cs, added the following to Configure:

app.UseAuthentication();
app.UseAuthorization();

I did install the Microsoft.AspNetCore.Authenticate.Negotiate package.

Created the Authorization handler and requirement:

public class AuthorizedUserHandler: AuthorizationHandler<AuthorizedUserRequirement>
{
    private readonly AuthorizationConfiguration _configuration;

    public AuthorizedUserHandler(AuthorizationConfiguration configuration)
    {
        _configuration = configuration;
    }

    protected override Task HandleRequirementAsync(AuthorizationHandlerContext context, AuthorizedUserRequirement requirement)
    {
        if (context.User.IsInRole(_configuration.User.Group))
        {
            // Call 'Succeed' to mark current requirement as passed
            context.Succeed(requirement);
        }

        return Task.CompletedTask;
    }
}
public class AuthorizedUserRequirement: IAuthorizationRequirement { }

Then, I apply it to my controller to restrict access:

[Authorize(Policy = nameof(Policy.AuthorizedUser))]
public class CustomerController : Controller
{
}

My configuration object is correctly injected. However, context.User is empty. When I debug my project and go to a page that uses this policy (in Google Chrome), I get the HTTP ERROR 401 default error page from Google Chrome.

How can I modify my code to fix this error, or otherwise setup Windows Authentication for local debugging on MacOS? I also tried using the Windows Authentication schema in services.AddAuthentication but that also failed.

0 Answers
Related