I have an ASP.NET 5.0 application and I am using IdentityServer4 for authentication and authorization.
I am setting the token lifetime for reset password to 20 minutes as below in the startup:
//ResetPasswordTokenLifetime
services.Configure<DataProtectionTokenProviderOptions>(options => options.TokenLifespan = TimeSpan.FromMinutes(20);
here is how I am validating the token
await this._userManager.VerifyUserTokenAsync(user, this._userManager.Options.Tokens.PasswordResetTokenProvider, "ResetPassword", token)
But when I send the token for resetting password it expires after 8 minutes(I assume this is the default value?) can you please help me with figuring out what am I missing?
this is full configurService in StartUp
public void ConfigureServices(IServiceCollection services)
{
services.AddControllersWithViews();
//Connection String
services.AddDbContext<AppIdentityContext>(options => options.UseSqlServer(Configuration.GetConnectionString("PortalConnectionString")));
//Dependency Injection
services.Configure<IdentityApplicationSettings>(Configuration.GetSection("AppSettings"));
services.AddScoped<IEventSink, AppEventSink>();
services.AddTransient<IAppUserValidator<AppUser>, AppUserValidator<AppUser>>();
//AspNetIdentity Configuration
services.AddIdentity<AppUser, IdentityRole>(options =>
{
options.User.RequireUniqueEmail = false;
options.Lockout.MaxFailedAccessAttempts = Configuration.GetSection("AppSettings").GetValue<Int32>("MaxFailedAccessAttempts");
//todo change the timespan
options.Lockout.DefaultLockoutTimeSpan = TimeSpan.FromDays(360 * 100);
options.Password.RequiredLength = 8;
options.Password.RequireDigit = true;
options.Password.RequireUppercase = true;
options.Password.RequireLowercase = true;
options.Password.RequireNonAlphanumeric = true;
})
.AddUserManager<AppUserManager>()
.AddEntityFrameworkStores<AppIdentityContext>()
.AddDefaultTokenProviders();
//IdentityServer Configuration
var migrationsAssembly = typeof(Startup).GetTypeInfo().Assembly.GetName().Name;
var builder = services.AddIdentityServer(options =>
{
options.Events.RaiseErrorEvents = true;
options.Events.RaiseInformationEvents = true;
options.Events.RaiseFailureEvents = true;
options.Events.RaiseSuccessEvents = true;
options.UserInteraction.LoginUrl = "/Account/Login";
options.UserInteraction.LogoutUrl = "/Account/Logout";
}).AddAspNetIdentity<AppUser>()
.AddProfileService<ProfileService>()
.AddInMemoryIdentityResources(Config.IdentityResources)
.AddInMemoryClients(Config.GetClients());
//ResetPasswordTokenLifetime
services.Configure<DataProtectionTokenProviderOptions>(options => options.TokenLifespan = TimeSpan.FromMinutes(Configuration.GetSection("AppSettings").GetValue<Int32>("ResetPasswordTokenLifetime")));
//CORS configuration
services.AddCors(options =>
{
options.AddPolicy("AllowAllOrigins", builder =>
{
builder.AllowAnyOrigin().AllowAnyMethod().AllowAnyHeader();
});
});
//Signing Credentials. Reading from tempkey saved on project for development, and from SSL certificate on Release
if (Environment.IsDevelopment())
{
builder.AddDeveloperSigningCredential();
}
else
{
builder.AddSigningCredential(loadCertificateFromStore());
}
}