Skip to content

API Auth via IdentityServer #10335

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
mkArtakMSFT opened this issue May 17, 2019 · 6 comments
Closed

API Auth via IdentityServer #10335

mkArtakMSFT opened this issue May 17, 2019 · 6 comments
Assignees
Labels
area-identity Includes: Identity and providers
Milestone

Comments

@mkArtakMSFT
Copy link
Contributor

details TBD but likely just adds IdentityServer & JWT middleware then

@mkArtakMSFT mkArtakMSFT added the area-identity Includes: Identity and providers label May 17, 2019
@mkArtakMSFT mkArtakMSFT added this to the 3.0.0-preview7 milestone May 17, 2019
@blowdart
Copy link
Contributor

@DamianEdwards this means template changes which aren't to simplify. So what do you want to do?

@SidShetye
Copy link

There is a related ticket open on the ASP.NET documentation about API security of an ASP.NET api application using IdentityServer (plus an SPA using said APIs).

The current VS templates are using the deprecated OAuth2 implicit flow instead of the OAuth2 OIDC PKCE flow. OAuth 2 is fairly complicated so if the ASP.NET API + authentication templates don't supply a simplified "pre-wired" starting point, it will simply promote bad practices. This "pre-wired" template is especially important because currently identity server 4's documentation is broken against ASP.NET 3.0, adding even more pain.

@Pilchie
Copy link
Member

Pilchie commented Jul 10, 2019

Ping on this, since it's currently in Preview7, which doesn't seem likely at this point.

@Pilchie
Copy link
Member

Pilchie commented Aug 1, 2019

Moving to backlog since nothing has happened here.

@Pilchie Pilchie modified the milestones: 3.0.0-preview8, Backlog Aug 1, 2019
@HaoK
Copy link
Member

HaoK commented Oct 12, 2020

@blowdart is this tracking future work still?

@blowdart
Copy link
Contributor

Closing, because the whole thing needs a rethink anyway :)

@ghost ghost locked as resolved and limited conversation to collaborators Nov 11, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
area-identity Includes: Identity and providers
Projects
None yet
Development

No branches or pull requests

6 participants