ASP.NET Core authentication and authorization with OIDC without creating local copies of the user

Viewed 1688

I've just created a new ASP.NET Core application using Visual Studio, it has the authentication type set to "Individual Accounts":

enter image description here

I've added some code to handle OIDC:

builder.Services.AddAuthentication().AddOpenIdConnect(openIdOptions =>
{
    openIdOptions.ClientId = "myClientId";
    openIdOptions.Authority = "myAuthority";
    openIdOptions.ResponseType = OpenIdConnectResponseType.Code;
    openIdOptions.GetClaimsFromUserInfoEndpoint = false;
    openIdOptions.CallbackPath = "/signin-oidc";
    openIdOptions.SaveTokens = true;

Which is all well and good, I can click to login with OpenIdConnect:

openId connect login

When I log in with the provided credentials it pops up asking me to Associate my OpenIdConnect account:

enter image description here

I don't want to have to do this. Retrieving the access token and id token is sufficient for what I want to do, I don't require a local copy of the user. Being new to ASP.net and having not used Razor before it's not immediately obvious what code I should delete — if that's even the correct approach. I've played around with deleting various bits such as the Db setup as I don't really require it, although I suspect Razor does in some regard.

The Program.cs looks as follows:

var builder = WebApplication.CreateBuilder(args);

// Add services to the container.
var connectionString = builder.Configuration.GetConnectionString("DefaultConnection");
builder.Services.AddDbContext<ApplicationDbContext>(options =>
    options.UseSqlServer(connectionString));
builder.Services.AddDatabaseDeveloperPageExceptionFilter();

builder.Services.AddDefaultIdentity<IdentityUser>(options =>
    {
    })
    .AddEntityFrameworkStores<ApplicationDbContext>();
builder.Services.AddRazorPages();

builder.Services.AddAuthentication().AddGoogle(googleOptions =>
{
    googleOptions.ClientId = builder.Configuration["Authentication:Google:ClientId"];
    googleOptions.ClientSecret = builder.Configuration["Authentication:Google:ClientSecret"];
});

builder.Services.AddAuthentication().AddOpenIdConnect(openIdOptions =>
{
    openIdOptions.ClientId = "clientId";
    openIdOptions.Authority = "authority";
    openIdOptions.ResponseType = OpenIdConnectResponseType.Code;
    openIdOptions.GetClaimsFromUserInfoEndpoint = false;
    openIdOptions.CallbackPath = "/signin-oidc";
    openIdOptions.SaveTokens = true;
});


var app = builder.Build();

// Configure the HTTP request pipeline.
if (app.Environment.IsDevelopment())
{
    app.UseMigrationsEndPoint();
}
else
{
    app.UseExceptionHandler("/Error");
    app.UseHsts();
}

app.UseHttpsRedirection();
app.UseStaticFiles();

app.UseRouting();

app.UseAuthentication();
app.UseAuthorization();

app.MapRazorPages();

app.UseEndpoints(endpoints => { endpoints.MapControllerRoute("default", "{controller=Home}/{action=Index}"); });

app.Run();
0 Answers
Related