Dealing with token containing multiple "Roles" (ASP NET)

Viewed 163

I have a backend API that receives a token from a 3rd party (Azure). now the token will look something like this (shortened down for convenience).

Payload:

{
..........
"groups": [
"DbViewer",
"DbUser",
"DbAdmin",
"DbModerator"
],
"name": "John Fisher",
.......
}

I want to use the values in "groups" to authorize the users in the controllers. now the first issue I had was getting the "groups" type to become the "Roles". This is read can be fixed by setting the RoleClaim as such:

options.TokenValidationParameters = new TokenValidationParameters
{
     ValidateAudience = true,
     ValidAudience = Configuration["Jwt:Audience"],
     RoleClaimType ="groups"                  
 };

But my second problem I don't know how to solve and that is the fact that "groups" contains multiple roles so I don't think my controller class with [Authorize(Role = "DbAdmin")] will work.

Any idea how to fix this ?

0 Answers
Related