Can Azure AD B2C coexist with OWIN Identity?

Viewed 325

I want to use Azure AD B2C on my current ASP.NET MVC Web application without having to change too much.

The current app I'm working on uses Microsoft.AspNet.Identity.Owin with SignInManager and UserManager. It also uses Microsoft.AspNet.Identity to get the currently signed in user. The users are stored in the database using the dbo.AspNetUsers. Also roles and rights are defined in the database. This is why it's a lot of work to switch to B2C completely and I'm hoping there's a way between.

Is it possible to link the 2 so that when you're logged in with Azure AD B2C, you will also be logged in on the current Identity?

I tried to get it to work, but I still get errors on AntiForgeryToken and null values at System.Web.HttpContextBase.User.Identity.

So first question: can Owin and B2C coexist in the way I need it to?

and secondly: is there a way to store the cookies for the previous way with Owin based on the emailaddress that's logged in with B2C?

EDIT: Something else I tried is to redirect to an action where I can sign in the logged in user with my old authentication system too. It looks like this:

    [AllowAnonymous]
    public async Task<ActionResult> ExternalB2CLogin()
    {
        if (ClaimsPrincipal.Current != null && ClaimsPrincipal.Current.Claims.Any())
        {
            var email = ClaimsPrincipal.Current.Claims.Where(c => c.Type == "emails").FirstOrDefault().Value;

            var user = await SignInManager.UserManager.FindByEmailAsync(email);
            
            SignInManager.SignIn(user, true, true);
            UserService.UpdateLastLogin(email);
            await UpdateClaims(user.Id);

            return RedirectToLocal("/");
        }

        return RedirectToAction("Login");
    }

Only problem is that if I add it like this:

Redirect Uri Azure AD B2C

Then it always redirects to that action. What I want is that B2C only redirects to this action after a successful login.

Does anyone have an idea how to configure that?

EDIT: So basically I want the flow to go like this:

  1. User comes on "/",
  2. Because not logged in to OWIN Identity gets Redirected to "/Account/Login"
  3. Then chooses to login with AAD B2C, which goes to the B2C url
  4. User logs in on B2C login page
  5. Logged in user gets redirected to "/Account/ExternalB2CLogin"
  6. ExternalB2CLogin method also logs in to OWIN Identity, then redirects to "/"
  7. Now the user is logged in to both B2C and OWIN Identity in the DB
0 Answers
Related