Signed in to multiple authentication schemes simultaneously in ASP.NET Core 3.1 web app

Viewed 236

I'm developing a web app that integrates two systems, let's call them SystemA and SystemB. Both systems are protected using OAuth2.

Since the web app communicates with both SystemA and SystemB, the user has to be signed it to both systems at the same time. I can't figure out how to achieve this by using the Authorize attribute only. It seems like the authentication is successful if the user is signed in to one of the authentication schemes, but I need the user to be signed in to both authentication schemes.

A workaround is to programmatically check if the user is signed in to a specific authentication scheme and then do Challenge whether or not the user is signed in, but I don't really like this workaround.

Example code:

Startup.cs

services.AddAuthentication()
    .AddOAuth("SystemA", options => {})
    .AddOAuth("SystemB", options => {});
    
services.AddAuthorization(options =>
{
    var policy = new AuthorizationPolicyBuilder("SystemA", "SystemB");
    policy = policy.RequireAuthenticatedUser();
    options.DefaultPolicy = policy.Build();
}); 

Controller

[HttpGet]
[Route("test")]
[Authorize(AuthenticationSchemes = "SystemA,SystemB")]
public IActionResult Test()
{
    // here I want the user to be authenticated to both SystemA and SystemB!
    // but only one of the authentication schemes is authenticated
    return Ok();
}

I would really appreciate any guidance!

0 Answers
Related