Share JWT Token between .Net Core 5 Web API

Viewed 529

I have 2 WebAPI .Net Core 5, both implementing JWT token.

The 2 projects have the same ValidAudience, ValidIssuer, IssuerSigningKey, the same Claims.

The app1 has a Login method that generates a Token.

Can i use this Token for an HTTP call from app1 to a controller in app2 with [Authorize] as a header in the controller?

I tried but it seems no: i suppose that app2 should have a login that generates a Token given to app1 so app1 uses this token to call a controller in app2, otherwise no way. or no?

In practice an SSO scenario, about that i never made experiences (please give links about...)

2 Answers

One option when you want to communicate between API1 and API2 is to use the client credentials flow between these two services. Then these two API's can freely communicate even when there is no user involved, like I show in the picture below:

enter image description here

Can i use this Token for an HTTP call from app1 to a controller in app2 with [Authorize] as a header in the controller?

Yes, you can.

My sample test project

//ConfigureServices    
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme).AddJwtBearer(options => {
                    var secretByte = Encoding.UTF8.GetBytes("Authentication:SecretKey");
                    options.TokenValidationParameters = new TokenValidationParameters
                    {
                        ValidateIssuer = true,
                        ValidIssuer = "Authentication:Issuer",
                        ValidateAudience = true,
                        ValidAudience = "Authentication:Audience",
                        ValidateLifetime = true,
                        IssuerSigningKey = new SymmetricSecurityKey(secretByte),
                        ClockSkew = TimeSpan.Zero
                   };
  });

 //Configure method
 ...
 app.UseAuthorization();

Generate jwt token.

    public IActionResult login(string name,string pwd)
    {
        if (name == "jason" && pwd == "test")
        {
            var singningAlgorithm = SecurityAlgorithms.HmacSha256;
            var claims = new[] { 
       new Claim(JwtRegisteredClaimNames.Sub,"861826225")
       };
            var secretByte = Encoding.UTF8.GetBytes("Authentication:SecretKey");
            var signingkey = new SymmetricSecurityKey(secretByte);
            var signingCredentials = new SigningCredentials(signingkey, singningAlgorithm);
            var token = new JwtSecurityToken(
                issuer: "Authentication:Issuer",
                audience: "Authentication:Audience",
                claims,
                notBefore: DateTime.Now,
                expires: DateTime.Now.AddSeconds(30),
                signingCredentials
                );

            var tokenStr = new JwtSecurityTokenHandler().WriteToken(token);

            return Ok(tokenStr);
        }
        else {
            return Ok("user info not matched");
        }
    }

Test Result:

enter image description here

enter image description here

Related Bolg:

JWT Auth in ASP.NET Core

Related