I'm currently trying to get Openiddict working in the following scenario:
My resource-API is also the one responsible for hosting the authorize Openiddict stack (so that every API is completely self-contained and not relying on a central IDP).
Multiple client apps are accessing this API with different permissions based on the client app and the user using this client app. So to get this abstract setup a little more clear here is a simple example:
- Resource-API (this will also host Openiddict): MyApi
- Client-App: MyClientApp1
- Client-App: MyClientApp2
- User: MyUser1
- User: MyUser2
MyApi will have these example endpoints:
- OnlyForMyClientApp1
- OnlyForMyClientApp2
- OnlyForMyClientApp1AndMyUser1
- OnlyForMyClientApp1AndMyUser2
- OnlyForMyClientApp2AndMyUser1
- OnlyForMayClientApp2AndMyUser2
I get the client credentials flow and the authorization code flow with integrated win-auth up and running by looking at the Openiddict samples, but only on their own and not combined.
But I don't know how I get both flows working in conjunction together.