My client application i.e. webchat uses openid authentication and generated access token is also passed to bot to use while calling graph apis.
start up Code:
services.AddAuthentication(options =>
{
options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
})
//.AddAzureAd(options => this.Configuration.Bind("Authentication:AzureAd", options))
.AddCookie()
.AddOpenIdConnect(options =>
{
options.ClientId = "cid";
options.ClientSecret = "csercet";
options.Authority = string.Format(azureAdConfig.Instance, azureAdConfig.TenantId);
options.ResponseType = OpenIdConnectResponseType.CodeIdToken;
options.Resource = "https://graph.microsoft.com/";
options.Events = new AuthEvents(azureAdConfig);
});
Once Authorization code is recieved in authevents then Access Token is generated :
public override async Task AuthorizationCodeReceived(AuthorizationCodeReceivedContext context)
{
var principal = context.Principal;
var request = context.HttpContext.Request;
var currentUri = UriHelper.BuildAbsolute(request.Scheme, request.Host, request.PathBase, request.Path);
var tokenService = (ITokenService)context.HttpContext.RequestServices.GetService(typeof(ITokenService));
try
{
var x = await tokenService.RequestTokenAsync(principal, context.ProtocolMessage.Code, currentUri, "https://graph.microsoft.com/")
.ConfigureAwait(false);
context.HandleCodeRedemption(x.AccessToken, x.IdToken);
}
catch (System.Exception ex)
{
throw;
}
}
How to get new token on expiry of access token in .net core 3.1 ?
If i try to use AcquiretokenAsync method then it requires PlatformParameters as a paramater which expects to implement interface ICustomWebUi.
I dont see any use of its implementation so i passed null but getting error as customWebUi can not be passed as null.
Code:
result = await authContext.AcquireTokenAsync(resource, "clientid", new Uri(redirectURI), new PlatformParameters(PromptBehavior.RefreshSession, null));
Parameters class :
#region Assembly Microsoft.IdentityModel.Clients.ActiveDirectory, Version=5.2.8.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
// C:\Users\v-sagkul\.nuget\packages\microsoft.identitymodel.clients.activedirectory\5.2.8\lib\netstandard1.3\Microsoft.IdentityModel.Clients.ActiveDirectory.dll
#endregion
using Microsoft.IdentityModel.Clients.ActiveDirectory;
using Microsoft.IdentityModel.Clients.ActiveDirectory.Extensibility;
namespace Microsoft.IdentityModel.Clients.ActiveDirectory
{
//
// Summary:
// Additional parameters used in acquiring user's authorization.
public class PlatformParameters : IPlatformParameters
{
//
// Summary:
// Constructor that allows extends to configure their own web ui. Not implemented
// on Android, iOS and UWP.
//
// Parameters:
// promptBehavior:
// Controls the prompt that is displayed on web ui. Default is Microsoft.IdentityModel.Clients.ActiveDirectory.PromptBehavior.SelectAccount.
//
// customWebUi:
// Custom implementation of the web ui
//
// Remarks:
// This object is platform specific and should not be constructed from NetStandard
// (shared) assemblies.
public PlatformParameters(PromptBehavior promptBehavior, ICustomWebUi customWebUi);
//
// Summary:
// Gets the configured prompt behavior
public PromptBehavior PromptBehavior { get; }
//
// Summary:
// Extension method enabling ADAK.NET extenders for public client applications to
// set a custom web ui that will let the user sign-in with Azure AD, present consent
// if needed, and get back the authorization code.
public ICustomWebUi CustomWebUi { get; }
}
}