I have been trying to figure out how to do API JWT token signature validation on user based token from a Single Page Application that interacts with Multiple RESTful Resource API's which leverages the Microsoft Identity platform. The authentication of the SPA uses Authorization Code flow. Each application (SPA and two RESTful API's) has its own app registration (i.e. separate Client ID's)
Per, reading (Microsoft Graph API authorization error: Invalid Audience), it appears that if you cross client_id's (i.e WebUI (clientid1) to resource API (clientid2)) you have add an additional scope associated the API - (i.e. api://72b2..../Location...). If this is not done signature validation fails on the API. Here is a sample snippet of code that verifies the token using the jsonwebtoken library
jwt.verify(token.trim(), this._public_key, { algorithms: list_algorithms }, (err, decoded) => {
if (err) {
return reject(err);
}
resolve(decoded);
});
Moreover, the defining of scopes in the SPA are limited to one api, so if you have multiple API's you cannot add additional API scopes in the SPA. Hence the challenge I am running into.
The Angular 12.0 SPA leverages the library angular-oauth2-oidc, and the API's are NodeJS / Express based applications and I have full control over the source code.
With other Identity platforms such as PingFederate and OAuth, I was able to do JWT signature validation in the API's without issue.
Since introspection is not supported by Microsoft (https://docs.microsoft.com/en-us/answers/questions/115061/does-azure-provide-any-oauth-2-token-introspection.html), I felt that this was an important check to have.
If there is no way to do this validation, I will most likely have to setup a proxy API to manage the interaction with the different resource API's, instead of managing this in my SPA.
If you need more information or code, I can provide this, and I will provide this right away.