I recently switched from a Windows machine with Visual Studio to a MacBook with Rider. I have a .NET Core 3.1 project that I upgraded from .NET Framework 4.7.2, and I am trying to configure Windows Authentication for it.
My MacBook is connected to a company domain via Enterprise Connect, and I have active kerboros tickets. AKA, I am able to access company resources that use Windows Authentication or otherwise pull my domain credentials. For example, I can login to the published version of my project which runs on IIS and .NET Framework 4.7.2.
However, I am not able to use Windows Authentication when I run the .NET Core 3.1 version locally. I have made the following changes to my project:
In StartUp.cs, added the following to ConfigureServices:
services.AddAuthentication(NegotiateDefaults.AuthenticationScheme).AddNegotiate();
services.AddAuthorization(options =>
{
options.AddPolicy(nameof(Policy.AuthorizedUser),
policy => policy.Requirements.Add(new AuthorizedUserRequirement()));
});
services.AddSingleton<IAuthorizationHandler, AuthorizedUserHandler>();
In StartUp.cs, added the following to Configure:
app.UseAuthentication();
app.UseAuthorization();
I did install the Microsoft.AspNetCore.Authenticate.Negotiate package.
Created the Authorization handler and requirement:
public class AuthorizedUserHandler: AuthorizationHandler<AuthorizedUserRequirement>
{
private readonly AuthorizationConfiguration _configuration;
public AuthorizedUserHandler(AuthorizationConfiguration configuration)
{
_configuration = configuration;
}
protected override Task HandleRequirementAsync(AuthorizationHandlerContext context, AuthorizedUserRequirement requirement)
{
if (context.User.IsInRole(_configuration.User.Group))
{
// Call 'Succeed' to mark current requirement as passed
context.Succeed(requirement);
}
return Task.CompletedTask;
}
}
public class AuthorizedUserRequirement: IAuthorizationRequirement { }
Then, I apply it to my controller to restrict access:
[Authorize(Policy = nameof(Policy.AuthorizedUser))]
public class CustomerController : Controller
{
}
My configuration object is correctly injected. However, context.User is empty. When I debug my project and go to a page that uses this policy (in Google Chrome), I get the HTTP ERROR 401 default error page from Google Chrome.
How can I modify my code to fix this error, or otherwise setup Windows Authentication for local debugging on MacOS? I also tried using the Windows Authentication schema in services.AddAuthentication but that also failed.