Is it possible to have Apple SignIn as another external authentication provider with Identity server 4?
I have Id server configured to secure the web api's and it's working well with Google.
But not working as expected with Apple, it seems to be logging me in but doesn't look like persisting the token.
My existing code
.AddOpenIdConnect("Apple", async options =>
{
options.ResponseType = "code";
options.SignInScheme = IdentityServerConstants.ExternalCookieAuthenticationScheme;
options.DisableTelemetry = true;
options.Scope.Clear();
options.Scope.Add("name");
options.Scope.Add("email");
options.Configuration = new OpenIdConnectConfiguration
{
AuthorizationEndpoint = "https://appleid.apple.com/auth/authorize",
TokenEndpoint = "https://appleid.apple.com/auth/token"
};
options.ClientId = "<service id>";
options.Events.OnAuthorizationCodeReceived = context =>
{
context.TokenEndpointRequest.ClientSecret = AppleSignInTokenGenerator.CreateNewToken();
return Task.CompletedTask;
};
options.TokenValidationParameters.ValidIssuer = "https://appleid.apple.com";
var jwks = await new HttpClient().GetStringAsync("https://appleid.apple.com/auth/keys");
options.TokenValidationParameters.IssuerSigningKeys = new JsonWebKeySet(jwks).Keys;
options.ProtocolValidator.RequireNonce = false;
});
public static class AppleSignInTokenGenerator
{
public static string CreateNewToken()
{
const string iss = "<apple dev team account id>";
const string aud = "https://appleid.apple.com";
const string sub = "<service id>";
const string privateKeyContentn = "private key content";
var cngKey = CngKey.Import(Convert.FromBase64String(privateKeyContentn), CngKeyBlobFormat.Pkcs8PrivateBlob);
var handler = new JwtSecurityTokenHandler();
var token = handler.CreateJwtSecurityToken(
issuer: iss,
audience: aud,
subject: new ClaimsIdentity(new List<Claim>
{
new Claim("sub", sub)
}),
expires: DateTime.UtcNow.AddMinutes(30), // expiry can be a maximum of 6 months => generate one per request, or one and then re-use until expiration
issuedAt: DateTime.UtcNow,
notBefore: DateTime.UtcNow,
signingCredentials: new SigningCredentials(new ECDsaSecurityKey(new ECDsaCng(cngKey)), SecurityAlgorithms.EcdsaSha256));
return handler.WriteToken(token);
}
}