I am trying to get an Azure token from an internal tool at work but it responds with:
statusCode: 400
ResponseBody: {
"error":"invalid_request",
"error_description":"AADSTS9002327: Tokens issued for the 'Single-Page Application' client-type may only be redeemed via cross-origin requests.
}
Code
var builder = PublicClientApplicationBuilder.Create(ClientId)
.WithAuthority($"{Instance}{Tenant}")
.WithRedirectUri("https://login.microsoftonline.com/common/oauth2/nativeclient")
//.WithRedirectUri("http://localhost:8080")
.WithDefaultRedirectUri();
var app = builder.Build();
IAccount account = PublicClientApplication.OperatingSystemAccount;
AuthenticationResult authResult = null;
try
{
Console.WriteLine("Trying AcquireTokenSilent");
authResult = await app.AcquireTokenSilent(scopes, account)
.ExecuteAsync();
Console.WriteLine("authResult = {0}", authResult);
}
catch (MsalUiRequiredException ex)
{
Console.WriteLine("caught MsalUiRequiredException ex = {0}", ex);
try
{
Console.WriteLine("Trying AcquireTokenInteractive");
authResult = await app.AcquireTokenInteractive(scopes)
.WithAccount(account)
.WithPrompt(Prompt.SelectAccount)
.ExecuteAsync();
Console.WriteLine("authResult = {0}", authResult);
}
catch (MsalException msalex)
{
Console.WriteLine($"Error Acquiring Token:{System.Environment.NewLine}{msalex}");
}
}
I added this line below because I was previously getting this error:
"ErrorCode: loopback_redirect_uri Microsoft.Identity.Client.MsalClientException: Only loopback redirect uri is supported, but https://login.microsoftonline.com/common/oauth2/nativeclient was found. Configure http://localhost or http://localhost:port both during app registration and when you create the PublicClientApplication object. See https://aka.ms/msal-net-os-browser for details"
''' .WithRedirectUri("http://localhost:8080")'''
I tried http://localhost also and pinged the team that wrote the tool to see what redirect they use in the azure setup.
I am new to c# so I am pretty well stuck at this point but I think I need Cors.
https://docs.microsoft.com/en-us/aspnet/core/security/cors?view=aspnetcore-3.1
I'm using ... net5.0