Skip to content

Authorization Code Flow  #33

@rajeevchib

Description

@rajeevchib

We need to use Authorization Code Flow for existing ASP.Net Web Forms Application. We were trying to follow this sample.

This sample is using ResponseType - OpenIdConnectResponseType.CodeIdToken.

We were assuming that for using Authorization Code Flow, we need to use ResponseType Code, not CodeIdToken.

But if we change ResponseType to Code in UseOpenIdConnectAuthentication, we get following error:

AADSTS9002313: Invalid request. Request is malformed or invalid.
Trace ID: 9bdf8e16-5395-4358-a21f-890631a05b00
Correlation ID: 7938070f-2b7b-4a17-898e-96184c770153
Timestamp: 2021-03-23 20:22:05Z

Also, In App Registration screen on Azure Portal, We have to select Access Tokens. I think that is not recommended for ASP.Net Web applications.

image

But If we deselect Access Tokens Option (as we don't want to use Implicit Flow), we get following error:

OpenIdConnectMessage.Error was not null, indicating an error. Error: 'unauthorized_client'. Error_Description (may be empty): 'AADB2C90057: The provided application is not configured to allow the 'OAuth' Implicit flow.
Correlation ID: c9279b25-8857-414f-bf61-6e6ffcb10f5d
Timestamp: 2021-03-24 07:39:29Z
'. Error_Uri (may be empty): 'error_uri is null'.

Please suggest if we are missing some settings or configurations.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions