Problem with custom claims when Windows authentication is used

Viewed 236

I'm trying to implement Windows authentication for Identity Server 4.

In my code, I use similar solutions to the one described in Identity server 4 windows authentication using extension Grant not working

First of all, I use the HttpSys server with a proper scheme

builder.WebHost.UseHttpSys(options =>
{
    options.Authentication.Schemes = AuthenticationSchemes.Negotiate | AuthenticationSchemes.NTLM;;
    options.Authentication.AllowAnonymous = false;    
});

then I add Negotiate for Authentication:

builder.Services.AddAuthentication(IdentityServerConstants.LocalApi.AuthenticationScheme)
    .AddIdentityServerAuthentication(options =>
    {        
        options.Authority = "http://localhost:5000";
        options.ApiName = "server.api";
    })
    .AddNegotiate()
    .AddLocalApi();

I also extend Identity Server with such code:

.AddExtensionGrantValidator<WinAuthGrantValidator>()

(the code of WinAuthGrantValidator can be found in this answer Identity server 4 windows authentication using extension Grant not working)

This seems to work and the user is authenticated. WindowsIdentity is in HttpContext.User.Identity - so far, so good.

Now is my problem, I have also registered ProfileService in the Identity Server 4 like so:

.AddProfileService<ProfileService>()

which adds some data to the logged in user (as an additional Claim) - this works if the user is logged in with username and password.

Unfortunately when I use Windows Authentication for logging, then ProfileService is invoked and adds some claims to IssuedClaims but later (in application code) I try to read those Claims from HttpContext.User it doesn't have it. Would you help me figure out why this is happening?

Thanks a lot!

0 Answers
Related