【发布时间】:2019-06-28 02:10:43
【问题描述】:
我正在尝试将 Azure AD 与 Piranha CMS 集成以进行身份验证。
这是我目前的配置:
启动
public IServiceProvider ConfigureServices(IServiceCollection services) {
services.AddPiranhaImageSharp();
services.AddPiranhaEF(options => options.UseMySql(Configuration["ConnectionStrings:DefaultConnection"]));
services.AddPiranhaIdentityWithSeed<IdentityMySQLDb>(
options => options.UseMySql(Configuration["ConnectionStrings:DefaultConnection"]));
services.AddPiranhaManager();
services.AddAuthentication(options =>
{
options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
options.DefaultChallengeScheme = OpenIdConnectDefaults.AuthenticationScheme;
}).AddOpenIdConnect(options =>
{
options.Authority = "https://login.microsoftonline.com/" + this.TenantId;
options.ClientId = this.ClientId;
options.ResponseType = OpenIdConnectResponseType.IdToken;
options.CallbackPath = "/signin-callback";
options.SignedOutRedirectUri = "https://localhost:5001/";
options.SaveTokens = true;
options.Events.OnTokenValidated = async context => { await TokenValidated(context); };
}).AddCookie();
}
通过上述配置,我设法使用 Azure AD 对公共网站的用户进行身份验证。
当我尝试访问 manager 区域时,我无法使用默认用户/密码组合访问它。这是我需要一点帮助的地方。
稍后编辑:
为了让两者都能正常工作,我做了以下更改:
services.AddAuthentication(/*specify no options, leave defaults*/)
.AddOpenIdConnect(options =>
{
options.Authority = "https://login.microsoftonline.com/" + this.TenantId;
options.ClientId = this.ClientId;
options.ResponseType = OpenIdConnectResponseType.IdToken;
options.CallbackPath = "/signin-callback";
options.RemoteSignOutPath = "/signout-oidc";
options.SignedOutRedirectUri = "https://localhost:5001/";
options.SignedOutCallbackPath = "/signout-callback";
options.SignOutScheme = OpenIdConnectDefaults.AuthenticationScheme;
options.Events.OnTokenValidated = async context => { await TokenValidated(context); };
})
.AddCookie(options => options.Cookie.SameSite = SameSiteMode.None);
然后,当我尝试登录/注销时,我创建了一个 SecurityController,如下所示:
public class SecurityController : Controller
{
public IActionResult Login()
{
return Challenge(new AuthenticationProperties
{
RedirectUri = "/about"
}, OpenIdConnectDefaults.AuthenticationScheme);
}
public async Task<IActionResult> Logout()
{
await HttpContext.SignOutAsync("Identity.External");
return Redirect("/");
}
}
【问题讨论】:
标签: asp.net-core azure-active-directory piranha-cms