Upgrading Microsoft.Owin.Security broke UseOpenIdConnectAuthentication

Viewed 74

I have upgraded my .NET Framework 4.6.1 application by bumping Microsoft.Owin.Security packages from 3.0.1 to 4.2.2. When I did, my authentication no longer works. I'm now hitting the AuthenticationFailed section and I am blocked hitting my controller method. I have no idea why this happened or how to troubleshoot the issue. It's a black box. Any help is greatly appreciated.

startup.cs

    public void Configuration(IAppBuilder app)
        {
            //User authentication setup
            app.SetDefaultSignInAsAuthenticationType(CookieAuthenticationDefaults.AuthenticationType);

            app.UseCookieAuthentication(new CookieAuthenticationOptions());                       

            app.UseOpenIdConnectAuthentication(
                new OpenIdConnectAuthenticationOptions
                {
                    ClientId = clientId,
                    Authority = $"{aadInstance}{tenant}",
                    PostLogoutRedirectUri = postLogoutRedirectUri,

                    TokenValidationParameters = new TokenValidationParameters
                    {
                        RoleClaimType = "roles",
                    },

                    Notifications = new OpenIdConnectAuthenticationNotifications
                    {
                        AuthenticationFailed = context =>
                        {
                            context.HandleResponse();
                            context.Response.Redirect("/Error");
                            return Task.FromResult(0);
                        }
                    }
                });
        }

Update: I realized there was an exception returned.

{"IDX21323: RequireNonce is '[PII is hidden]'. OpenIdConnectProtocolValidationContext.Nonce was null, OpenIdConnectProtocol.ValidatedIdToken.Payload.Nonce was not null. The nonce cannot be validated. If you don't need to check the nonce, set OpenIdConnectProtocolValidator.RequireNonce to 'false'. Note if a 'nonce' is found it will be evaluated."}

I found some code that fixed the issue for some, but for me it just got into an infinite loop.

Notifications = new OpenIdConnectAuthenticationNotifications
                {
                    AuthenticationFailed = context =>
                     {
                         if (context.Exception.Message.Contains("IDX21323"))
                         {
                             context.HandleResponse();
                             context.OwinContext.Authentication.Challenge();
                         }

                         return Task.FromResult(true);
                     }
                }
1 Answers

I figured out the problem. OWIN 4.0 started adding a nonce into the openid connect authentication request. In my local development environment I was not running under https. It appears that I was being authenticated properly, but the nonce was not being included in the response... maybe excluded due to PII. So the verification on the client side was failing due to a missing nonce. Once I changed to using https, everything started working again.

Related