how to set authorize attribute by source application/URL

Viewed 48

I have a .NET core web API server that I am communicating with (post/get) from two applications. The first is an angular website and the second one is a WPF app. I want the angular website to get response only with JWT Token Bearer and the WPF to get the responses without any need for Authorization. should I create two controllers? one without Authorize attribute for WPF and one with Authorize attribute for angular? or there is another way to do it with custom Authorize attribute that check if request come from angular or from WPF?

Thanks :)

1 Answers

If you do not require the WPF client to authenticate, this means that you need to open the methods for anonymous access.

For this to work, you do not have to create two controllers, but can use the authorization attributes Authorize and AllowAnonymous to decide which methods require an authenticated user (Angular) and an unauthenticated one (WPF).

Please note that if you use the AllowAnonymous attribute on a method in a controller with an Authorize attribute, AllowAnonymous overrides Authorize so that you can access the method without and authentication.

Related