We have implemented the MicrosoftGraphAuthProvider and it is all set up correctly as we have added an endpoint to output the authorized user's credentials using the following:
if (!IsAuthenticated) return null;
var session = this.Request.GetSession(true);
return session.ToJson();
This outputs my user, with the provider as microsoftgraph. Great, everything as expected.
However, when we add the authorization attribute:
[Authenticate("microsoftgraph")]
It returns a 401 and acts as if we are not logged in at all. All ss-id and ss-pid are sent in headers correctly, but it still returns a 401.
However, elsewhere in the system, we are using this same method to limit to API key auths
[Authenticate("apikey")]
We currently have 3 IAuthProviders loaded into the API.
Is there an issue in the provider itself or is there a different methodology behind limiting a service to microsfoftgraph provider?