Assertion is not within its valid time range. Ensure that the access token is not expired before using it for user assertion, or request a new token

Viewed 401

I am trying to generate access token using On-Behalf-Of flow which will be used to authenticate API calls. I am adding a claim called userIdToken which is value of id_token in startup file(sample below). Then retrieving the value from ClaimsPrincipal to to generate token using AcquireTokenOnBehalfOf method.

It works perfectly fine until userIdToken expires(1 hour). But it won't refresh the userIdToken and hence it throws exception when AcquireTokenOnBehalfOf method is called. Doing a fresh login works for next one hour since it uses new userIdToken .

How can I add token refresh functionality to the existing approach?

Error: Microsoft.Identity.Client.MsalUiRequiredException: 'AADSTS500133: Assertion is not within its valid time range. Ensure that the access token is not expired before using it for user assertion, or request a new token. Current time: 2022-06-16T10:33:17.8173399Z, expiry time of assertion 2022-06-16T06:49:33.0000000Z.

Startup.cs

services.AddAuthentication("SomeCustomType")
                .AddMicrosoftIdentityWebApp(options =>
                {
                    Configuration.Bind("AzureAD", options);
                    options.SaveTokens = true;

                    options.Events.OnTicketReceived = async context =>
                    {
                        var claimsIdentity = (ClaimsIdentity)context.Principal.Identity;
                        claimsIdentity.AddClaim(new Claim("DirectAadAuth", "true"));
                        
                        try
                        {
                            claimsIdentity.AddClaim(new Claim("userIdToken", context.Properties.GetTokens().First().Value));
                            var authedUser = new ClaimsPrincipal(new ClaimsIdentity(claimsIdentity.Claims, "SomeCustomType"));

                            await context.HttpContext.SignInAsync("CustomType", authedUser, new AuthenticationProperties{IsPersistent = true});
                        }
                        catch (System.Exception)
                        {
                          
                        }
                    };
                }
                )
                .EnableTokenAcquisitionToCallDownstreamApi(Configuration.GetSection("CustomConfig").Get<CustomConfigModel>().DownstreamApiScopes)
                .AddInMemoryTokenCaches();

TokenClient.cs

public async Task<string> GetAccessTokenAsync(ClaimsPrincipal user)
    {
        var userIdToken = user.Claims.FirstOrDefault(c => c.Type == "userIdToken")?.Value;
        var userAssertion = new UserAssertion(userIdToken);
        var scopedResult = await clientApplication.AcquireTokenOnBehalfOf(scopes, userAssertion).ExecuteAsync();
        
        return scopedResult.AccessToken;
        
    }
0 Answers
Related