|
| 1 | +# Identity Server 4 Integration |
| 2 | + |
| 3 | +**\*\*IMPORTANT NOTICE\*\*** |
| 4 | +Identity Server 4 maintainance stopped on November 2022, see [official announcement](https://identityserver4.readthedocs.io/en/latest/). Because of that, it is removed from ASP.NET Zero. We suggest migrating to OpenIddict. Check out ASP.NET Zero's [OpenIddict integration document](Infrastructure-Core-Angular-OpenIddict-Integration.md). |
| 5 | + |
| 6 | +[IdentityServer4](http://identityserver.io/) is an OpenID Connect and OAuth 2.0 framework for ASP.NET Core. ASP.NET Zero is integrated to IdentityServer4. It's **disabled by default**. Its located in `*.Web.Host` project. |
| 7 | + |
| 8 | +## Configuration |
| 9 | + |
| 10 | +You can enable/disable or configure it from **appsettings.json** file |
| 11 | + |
| 12 | +```json |
| 13 | +"IdentityServer": { |
| 14 | + "IsEnabled": "false", |
| 15 | + "Clients": [ |
| 16 | + { |
| 17 | + "ClientId": "client", |
| 18 | + "AllowedGrantTypes": [ "password" ], |
| 19 | + "ClientSecrets": [ |
| 20 | + { |
| 21 | + "Value": "def2edf7-5d42-4edc-a84a-30136c340e13" |
| 22 | + } |
| 23 | + ], |
| 24 | + "AllowedScopes": [ "default-api" ] |
| 25 | + }, |
| 26 | + { |
| 27 | + "ClientId": "demo", |
| 28 | + "ClientName": "MVC Client Demo", |
| 29 | + "AllowedGrantTypes": [ "hybrid", "client_credentials" ], |
| 30 | + "RequireConsent": "true", |
| 31 | + "ClientSecrets": [ |
| 32 | + { |
| 33 | + "Value": "def2edf7-5d42-4edc-a84a-30136c340e13" |
| 34 | + } |
| 35 | + ], |
| 36 | + "RedirectUris": [ "http://openidclientdemo.com:8001/signin-oidc" ], |
| 37 | + "PostLogoutRedirectUris": [ "http://openidclientdemo.com:8001/signout-callback-oidc" ], |
| 38 | + "AllowedScopes": [ "openid", "profile", "email", "phone", "default-api" ], |
| 39 | + "AllowOfflineAccess": "true" |
| 40 | + } |
| 41 | + ] |
| 42 | +} |
| 43 | +``` |
| 44 | + |
| 45 | +## Testing with Client |
| 46 | + |
| 47 | +ASP.NET Zero solution has a sample console application (ConsoleApiClient) that can connects to the application, authenticates through IdentityServer4 and calls an API. |
| 48 | + |
| 49 | + |
| 50 | + |
| 51 | +## Testing with MVC Client |
| 52 | + |
| 53 | +You can use [aspnet-zero-samples](https://github.com/aspnetzero/aspnet-zero-samples) -> `IdentityServerClient` project to test identity server with MVC client. |
| 54 | + |
| 55 | +Add a new client to `*.Web.Host` appsettings.json |
| 56 | + |
| 57 | +```json |
| 58 | +... |
| 59 | + { |
| 60 | + "ClientId": "mvcdemo", |
| 61 | + "ClientName": "MVC Client Demo 2", |
| 62 | + "AllowedGrantTypes": [ "implicit", "client_credentials" ], |
| 63 | + "RequireConsent": "true", |
| 64 | + "ClientSecrets": [ |
| 65 | + { |
| 66 | + "Value": "mysecret" |
| 67 | + } |
| 68 | + ], |
| 69 | + "RedirectUris": [ "http://localhost:62964/signin-oidc" ], |
| 70 | + "PostLogoutRedirectUris": [ "http://localhost:62964/signout-callback-oidc" ], |
| 71 | + "AllowedScopes": [ "openid", "profile", "email", "phone", "default-api" ], |
| 72 | + "AllowOfflineAccess": "true" |
| 73 | + } |
| 74 | +... |
| 75 | +``` |
| 76 | + |
| 77 | +Download the `IdentityServerClient` project and open it's `Startup.cs` and modify `AddOpenIdConnect` area as seen below |
| 78 | + |
| 79 | +```csharp |
| 80 | +... |
| 81 | +.AddOpenIdConnect("oidc", options => |
| 82 | +{ |
| 83 | + options.SignInScheme = "Cookies"; |
| 84 | + |
| 85 | + options.Authority = "https://localhost:44301";//change with your project url |
| 86 | + options.RequireHttpsMetadata = false; |
| 87 | + |
| 88 | + options.ClientId = "mvcdemo"; |
| 89 | + options.ClientSecret = "mysecret"; |
| 90 | + |
| 91 | + options.SaveTokens = true; |
| 92 | +}); |
| 93 | +... |
| 94 | +``` |
| 95 | + |
| 96 | + |
| 97 | + |
| 98 | +That is all. Now you can test it. |
| 99 | + |
| 100 | +Run both projects. Go to `IdentityServerClient` project's secure. <img src="images/identity-server-4-test-mvc-secure.png"> |
| 101 | + |
| 102 | +It will redirect you to the login page. |
| 103 | + |
| 104 | +<img src="images/identity-server-4-test-host-login.png"> |
| 105 | + |
| 106 | +After you successfully login, you will see the consent page. <img src="images/identity-server-4-test-host-consent.png"> |
| 107 | + |
| 108 | +After you allow consents, you will redirect to the secure page and get user claims. <img src="images/identity-server-4-test-mvc-secure-after-login.png"> |
| 109 | + |
| 110 | +## OpenId Connect Integration |
| 111 | + |
| 112 | +Once IdentityServer4 integration is enabled Web.Mvc application becomes an OpenId Connect server. That means another web application can use standard OpenId Connect protocol to authenticate users with your |
| 113 | +application and get permission to share their information (a.k.a. consent screen). |
| 114 | + |
| 115 | +## More |
| 116 | + |
| 117 | +See [IdentityServer4's own documentation](http://docs.identityserver.io/en/latest/) to understand and configure IdentityServer4. |
0 commit comments