I'm trying to publish an ASPNET Core/React SPA with individual accounts in a prod environment. The authentication works on my local development machine (I can log in and the app redirects me to the home page). On a published app it accepts the password but stays on the page as if it doesn't recognize that the user was authenticated. The code is below (essentially unchanged from the default template). Is there anything I need to add/fix to make it work? I'm publishing to smarterasp.net if it matters.
public class Program
{
public static IConfiguration? Configuration { get; private set; }
private static Serilog.ILogger logger;
public static void Main(string[] args)
{
var builder = WebApplication.CreateBuilder(args);
Configuration = builder.Configuration;
builder.Host.UseSerilog();
Log.Logger = new LoggerConfiguration()
.ReadFrom.Configuration(Configuration)
.MinimumLevel.Override("Microsoft", LogEventLevel.Information)
.Enrich.FromLogContext()
.CreateLogger();
builder.Host.UseSerilog(Log.Logger);
logger = Log.Logger;
ConfigureDbContext(builder);
ConfigureAuth(builder.Services);
builder.Services.AddControllersWithViews();
builder.Services.AddRazorPages();
ConfigureAndRunWebApp(builder);
}
private static void ConfigureAndRunWebApp(WebApplicationBuilder builder)
{
try
{
var app = builder.Build();
// Configure the HTTP request pipeline.
if (app.Environment.IsDevelopment())
{
app.UseMigrationsEndPoint();
}
else
{
// The default HSTS value is 30 days. You may want to change this for production scenarios, see https://aka.ms/aspnetcore-hsts.
app.UseHsts();
}
app.UseHttpsRedirection();
app.UseStaticFiles();
app.UseRouting();
app.UseAuthentication();
app.UseIdentityServer();
app.UseAuthorization();
app.MapControllerRoute(
name: "default",
pattern: "{controller}/{action=Index}/{id?}");
app.MapRazorPages();
app.MapFallbackToFile("index.html");
app.Run();
}
catch (Exception ex)
{
logger.Error(ex, "Failed to start the app");
throw;
}
}
private static void ConfigureDbContext(WebApplicationBuilder builder)
{
try
{
builder.Services.AddDbContext<ApplicationDbContext>(options => options.UseSqlServer(builder.Configuration.GetConnectionString("defaultConnection")));
builder.Services.AddDatabaseDeveloperPageExceptionFilter();
}
catch (Exception ex)
{
logger.Error(ex, "Failed to configure db");
throw;
}
}
private static void ConfigureAuth(IServiceCollection services)
{
try
{
services.AddDefaultIdentity<ApplicationUser>(options => options.SignIn.RequireConfirmedAccount = true)
.AddEntityFrameworkStores<ApplicationDbContext>();
services.AddIdentityServer()
.AddApiAuthorization<ApplicationUser, ApplicationDbContext>();
services.AddAuthentication()
.AddIdentityServerJwt();
}
catch (Exception ex)
{
logger.Error(ex, "Failed to configure auth");
throw;
}
}
}