Let's say I do have two projects that are containerized in Docker.
Project A - is already existing with some kind of OAuth implemented that is reaching Enterprise App registration within Azure AD (work account). I would like to not touch/change this project if possible.
Project B - is a REST API that I need to partially secure (part of endpoints will be still publicly/anonymously available). I don't care about policies/roles/claims - I wan't this super simple for beginning - whenever someone logged successfully in Project A, should be able to access any authorized endpoint in Project B.
Here is how the authentication is done in Project A:
services.AddAuthentication(options => {
options.DefaultScheme = CookieAuthenticationDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
})
.AddCookie()
.AddOpenIdConnect(options =>
{
options.ClientId = authSettings.AppId;
options.ClientSecret = authSettings.AppSecret;
options.MetadataAddress = $"https://login.microsoftonline.com/{authSettings.TenantId}/v2.0/.well-known/openid-configuration?appid={authSettings.AppId}";
options.Authority = $"https://login.microsoftonline.com/{authSettings.TenantId}/oauth2/v2.0";
options.ResponseType = "code";
options.GetClaimsFromUserInfoEndpoint = true;
options.TokenValidationParameters = new TokenValidationParameters {
NameClaimType = "name"
};
});
services.AddAuthorization(options => {
options.FallbackPolicy = new AuthorizationPolicyBuilder()
.RequireAuthenticatedUser()
.Build();
});
My questions are:
- How should I setup
Project Bto use information about authentication that was done inProject A? - How should I pass that information from
Project AtoProject Balong the request?