identityserver4 reset password token lifetime

Viewed 337

I have an ASP.NET 5.0 application and I am using IdentityServer4 for authentication and authorization.

I am setting the token lifetime for reset password to 20 minutes as below in the startup:

 //ResetPasswordTokenLifetime
            services.Configure<DataProtectionTokenProviderOptions>(options =>  options.TokenLifespan = TimeSpan.FromMinutes(20);

here is how I am validating the token

await this._userManager.VerifyUserTokenAsync(user, this._userManager.Options.Tokens.PasswordResetTokenProvider, "ResetPassword", token)

But when I send the token for resetting password it expires after 8 minutes(I assume this is the default value?) can you please help me with figuring out what am I missing?

this is full configurService in StartUp

public void ConfigureServices(IServiceCollection services)
        {
            services.AddControllersWithViews();

            //Connection String 
            services.AddDbContext<AppIdentityContext>(options => options.UseSqlServer(Configuration.GetConnectionString("PortalConnectionString")));

            //Dependency Injection 
            services.Configure<IdentityApplicationSettings>(Configuration.GetSection("AppSettings"));
            services.AddScoped<IEventSink, AppEventSink>();
            services.AddTransient<IAppUserValidator<AppUser>, AppUserValidator<AppUser>>();

            //AspNetIdentity Configuration 
            services.AddIdentity<AppUser, IdentityRole>(options =>
            {
                options.User.RequireUniqueEmail = false;
                options.Lockout.MaxFailedAccessAttempts = Configuration.GetSection("AppSettings").GetValue<Int32>("MaxFailedAccessAttempts");

                //todo change the timespan
                options.Lockout.DefaultLockoutTimeSpan = TimeSpan.FromDays(360 * 100);
                options.Password.RequiredLength = 8;
                options.Password.RequireDigit = true;
                options.Password.RequireUppercase = true;
                options.Password.RequireLowercase = true;
                options.Password.RequireNonAlphanumeric = true;
            })
              .AddUserManager<AppUserManager>()
              .AddEntityFrameworkStores<AppIdentityContext>()
              .AddDefaultTokenProviders();

            //IdentityServer Configuration 
            var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;

            var builder = services.AddIdentityServer(options =>
            {
                options.Events.RaiseErrorEvents = true;
                options.Events.RaiseInformationEvents = true;
                options.Events.RaiseFailureEvents = true;
                options.Events.RaiseSuccessEvents = true;
                options.UserInteraction.LoginUrl = "/Account/Login";
                options.UserInteraction.LogoutUrl = "/Account/Logout";
            }).AddAspNetIdentity<AppUser>()
            .AddProfileService<ProfileService>()
            .AddInMemoryIdentityResources(Config.IdentityResources)
            .AddInMemoryClients(Config.GetClients());


            //ResetPasswordTokenLifetime
            services.Configure<DataProtectionTokenProviderOptions>(options =>  options.TokenLifespan = TimeSpan.FromMinutes(Configuration.GetSection("AppSettings").GetValue<Int32>("ResetPasswordTokenLifetime")));


            //CORS configuration
            services.AddCors(options =>
            {
                options.AddPolicy("AllowAllOrigins", builder =>
                {
                    builder.AllowAnyOrigin().AllowAnyMethod().AllowAnyHeader();

                });
            });


            //Signing Credentials. Reading from tempkey saved on project for development, and from SSL certificate on Release
            if (Environment.IsDevelopment())
            {
                builder.AddDeveloperSigningCredential();

            }
            else
            {
                builder.AddSigningCredential(loadCertificateFromStore());
            }
        }
0 Answers
Related