I have a .NET 6 MVC application that is relying on AWS Cognito for its Authentication/Authorization.
The code is open-source and on GitHub.
The authentication setup code from Program.cs is:
builder.Services.AddAuthentication(options =>
{
options.DefaultScheme = "Cookies";
options.DefaultChallengeScheme = "oidc";
})
.AddCookie("Cookies")
.AddOpenIdConnect("oidc", options =>
{
options.Authority = authority;
options.RequireHttpsMetadata = false;
options.ClientId = clientId;
options.ClientSecret = clientSecret;
options.ResponseType = "code";
options.SaveTokens = true;
options.GetClaimsFromUserInfoEndpoint = true;
options.Scope.Clear();
options.Scope.Add("openid");
options.ClaimActions.MapUniqueJsonKey("role", "role");
options.TokenValidationParameters = new TokenValidationParameters { NameClaimType = "cognito:user", RoleClaimType = "cognito:groups" };
});
When I test the application locally:
dotnet run --project Bejebeje.Admin/Bejebeje.Admin.csproj
It runs fine without any issues. I can log in via AWS Cognito and I am taken back to my application and things just work.
However, my production deployed application doesn't work. It redirects me to AWS Cognito hosted UI, but after I input my creds, I am shown this:
The Client on AWS Cognito is set up like so:
The way I run my application on my production server is with this docker command:
docker run --name bejebeje-admin --env-file /var/www/html/admin.bejebeje.com/variables.env --network=bejebeje_net -p 5025:5000 -d bejebeje/admin:latest
I checked the docker logs of the container and I can see an error about invalid_client but I'm not sure why. I've tripled checked the client Id and Secret and they are correct.
{"EventId":52,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler","Message":"Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027, status code \u0027400\u0027.","State":{"Message":"Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027, status code \u0027400\u0027.","Error":"invalid_client","ErrorDescription":"error_description is null","ErrorUri":"error_uri is null","StatusCode":400,"{OriginalFormat}":"Message contains error: \u0027{Error}\u0027, error_description: \u0027{ErrorDescription}\u0027, error_uri: \u0027{ErrorUri}\u0027, status code \u0027{StatusCode}\u0027."}}
{"EventId":17,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler","Message":"Exception occurred while processing message.","Exception":"Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027. at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync()","State":{"Message":"Exception occurred while processing message.","{OriginalFormat}":"Exception occurred while processing message."}}
{"EventId":1,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware","Message":"An unhandled exception has occurred while executing the request.","Exception":"System.Exception: An error was encountered while handling the remote login. ---\u003E Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027. at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync() --- End of inner exception stack trace --- at Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler\u00601.HandleRequestAsync() at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task)","State":{"Message":"An unhandled exception has occurred while executing the request.","{OriginalFormat}":"An unhandled exception has occurred while executing the request."}}
{"EventId":13,"LogLevel":"Error","Category":"Microsoft.AspNetCore.Server.Kestrel","Message":"Connection id \u00220HMEHDSQR203P\u0022, Request id \u00220HMEHDSQR203P:00000002\u0022: An unhandled exception was thrown by the application.","Exception":"System.InvalidOperationException: The exception handler configured on ExceptionHandlerOptions produced a 404 status response. This InvalidOperationException containing the original exception was thrown since this is often due to a misconfigured ExceptionHandlingPath. If the exception handler is expected to return 404 status responses then set AllowStatusCode404Response to true. ---\u003E System.Exception: An error was encountered while handling the remote login. ---\u003E Microsoft.IdentityModel.Protocols.OpenIdConnect.OpenIdConnectProtocolException: Message contains error: \u0027invalid_client\u0027, error_description: \u0027error_description is null\u0027, error_uri: \u0027error_uri is null\u0027. at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.RedeemAuthorizationCodeAsync(OpenIdConnectMessage tokenEndpointRequest) at Microsoft.AspNetCore.Authentication.OpenIdConnect.OpenIdConnectHandler.HandleRemoteAuthenticateAsync() --- End of inner exception stack trace --- at Microsoft.AspNetCore.Authentication.RemoteAuthenticationHandler\u00601.HandleRequestAsync() at Microsoft.AspNetCore.Authentication.AuthenticationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task) --- End of inner exception stack trace --- at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.HandleException(HttpContext context, ExceptionDispatchInfo edi) at Microsoft.AspNetCore.Diagnostics.ExceptionHandlerMiddleware.\u003CInvoke\u003Eg__Awaited|6_0(ExceptionHandlerMiddleware middleware, HttpContext context, Task task) at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.Http.HttpProtocol.ProcessRequests[TContext](IHttpApplication\u00601 application)","State":{"Message":"Connection id \u00220HMEHDSQR203P\u0022, Request id \u00220HMEHDSQR203P:00000002\u0022: An unhandled exception was thrown by the application.","ConnectionId":"0HMEHDSQR203P","TraceIdentifier":"0HMEHDSQR203P:00000002","{OriginalFormat}":"Connection id \u0022{ConnectionId}\u0022, Request id \u0022{TraceIdentifier}\u0022: An unhandled exception was thrown by the application."}}

