ASP.NET Core Web API - can't authenticate - Getting 401 -

Viewed 153

I'm trying to call my ASP.NET Core Web API from a Vue3 app.

I have used the "connected services" in ASP.NET to configure AAD integration.

It has added the following code:

Program.cs

builder.Services
       .AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
       .AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd"))
       .EnableTokenAcquisitionToCallDownstreamApi()
       // .AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph"))
       .AddInMemoryTokenCaches();

appSettings.json:

"AzureAd": {
    "Instance": "https://login.microsoftonline.com/",
    "TenantId": "6a71XXXXXXf181",
    "ClientId": "b4476dXXXXXXX16f069",
    "Secret": "5b8XXXXX084caa",
    "Domain": "JXXXXXX5.onmicrosoft.com",
    "CallbackPath": "/signin-oidc",
    "ClientSecret": "Nvq8QXXXXXXXXXW0dA4",
    "ClientCertificates": []
  },

When I call the API from Vue (with a bearer token attached in headers), I get a HTTP 401 error:

WWW-Authenticate: Bearer error="invalid_token", error_description="The signature is invalid"

I have tried every sample I can find...but cannot get past this error.

Does anyone have a direction I can go in? Is this something wrong with App Registration?

Thanks in advance

1 Answers

We fixed it by issuing two tokens

one for the Microsoft Graph to get the user's image and other details and

second for calling the webAPI.

Please note you will have to put proper scopes in login request before getting the tokens.

Also check the token content to verify the audience and issuer, we used jwt.io to see the token details.

The whole credit goes to Adam.

Related