AWS Cognito with .NET 6 MVC app works locally but not on production

Viewed 406

I have a .NET 6 MVC application that is relying on AWS Cognito for its Authentication/Authorization.

The code is open-source and on GitHub.

The authentication setup code from Program.cs is:

builder.Services.AddAuthentication(options =>
    {
      options.DefaultScheme = "Cookies";
      options.DefaultChallengeScheme = "oidc";
    })
    .AddCookie("Cookies")
    .AddOpenIdConnect("oidc", options =>
    {
      options.Authority = authority;
      options.RequireHttpsMetadata = false;
      options.ClientId = clientId;
      options.ClientSecret = clientSecret;
      options.ResponseType = "code";
      options.SaveTokens = true;
      options.GetClaimsFromUserInfoEndpoint = true;
      options.Scope.Clear();
      options.Scope.Add("openid");
      options.ClaimActions.MapUniqueJsonKey("role", "role");
      options.TokenValidationParameters = new TokenValidationParameters { NameClaimType = "cognito:user", RoleClaimType = "cognito:groups" };
    });

When I test the application locally:

dotnet run --project Bejebeje.Admin/Bejebeje.Admin.csproj

It runs fine without any issues. I can log in via AWS Cognito and I am taken back to my application and things just work.

However, my production deployed application doesn't work. It redirects me to AWS Cognito hosted UI, but after I input my creds, I am shown this:

error

The Client on AWS Cognito is set up like so:

bejebeje-admin client on cognito

The way I run my application on my production server is with this docker command:

docker run --name bejebeje-admin --env-file /var/www/html/admin.bejebeje.com/variables.env --network=bejebeje_net -p 5025:5000 -d bejebeje/admin:latest

I checked the docker logs of the container and I can see an error about invalid_client but I'm not sure why. I've tripled checked the client Id and Secret and they are correct.

{"EventId":52,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler","Message":"Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027, status code \u0027400\u0027.","State":{"Message":"Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027, status code \u0027400\u0027.","Error":"invalid_client","ErrorDescription":"error_description is null","ErrorUri":"error_uri is null","StatusCode":400,"{OriginalFormat}":"Message contains error: \u0027{Error}\u0027, error_description: \u0027{ErrorDescription}\u0027, error_uri: \u0027{ErrorUri}\u0027, status code \u0027{StatusCode}\u0027."}}
{"EventId":17,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler","Message":"Exception occurred while processing message.","Exception":"Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027.    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest)    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()","State":{"Message":"Exception occurred while processing message.","{OriginalFormat}":"Exception occurred while processing message."}}
{"EventId":1,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware","Message":"An unhandled exception has occurred while executing the request.","Exception":"System.Exception: An error was encountered while handling the remote login.  ---\u003E Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027.    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest)    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()    --- End of inner exception stack trace ---    at Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler\u00601.HandleRequestAsync()    at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)    at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task)","State":{"Message":"An unhandled exception has occurred while executing the request.","{OriginalFormat}":"An unhandled exception has occurred while executing the request."}}
{"EventId":13,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Server.Kestrel","Message":"Connection id \u00220HMEHDSQR203P\u0022, Request id \u00220HMEHDSQR203P:00000002\u0022: An unhandled exception was thrown by the application.","Exception":"System.InvalidOperationException: The exception handler configured on ExceptionHandlerOptions produced a 404 status response. This InvalidOperationException containing the original exception was thrown since this is often due to a misconfigured ExceptionHandlingPath. If the exception handler is expected to return 404 status responses then set AllowStatusCode404Response to true.  ---\u003E System.Exception: An error was encountered while handling the remote login.  ---\u003E Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027.    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest)    at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()    --- End of inner exception stack trace ---    at Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler\u00601.HandleRequestAsync()    at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context)    at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task)    --- End of inner exception stack trace ---    at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.HandleException(HttpContext context, ExceptionDispatchInfo edi)    at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task)    at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.Http.HttpProtocol.ProcessRequests[TContext](IHttpApplication\u00601 application)","State":{"Message":"Connection id \u00220HMEHDSQR203P\u0022, Request id \u00220HMEHDSQR203P:00000002\u0022: An unhandled exception was thrown by the application.","ConnectionId":"0HMEHDSQR203P","TraceIdentifier":"0HMEHDSQR203P:00000002","{OriginalFormat}":"Connection id \u0022{ConnectionId}\u0022, Request id \u0022{TraceIdentifier}\u0022: An unhandled exception was thrown by the application."}}
0 Answers
Related