diff --git a/docs/en/Migration-Guides/OpenIddict-Blazor-Server.md b/docs/en/Migration-Guides/OpenIddict-Blazor-Server.md new file mode 100644 index 0000000000..89969e0dde --- /dev/null +++ b/docs/en/Migration-Guides/OpenIddict-Blazor-Server.md @@ -0,0 +1,170 @@ +# OpenIddict Blazor-Server UI Migration Guide + +## Blazor Project (Non-Tiered Solution) + +- In the **MyApplication.Blazor.csproj** replace **project references**: + + ```csharp + + + ``` + + with + + ```csharp + + ``` + +- In the **MyApplicationBlazorModule.cs** replace usings and **module dependencies**: + + ```csharp + using System; + using System.Net.Http; + using Volo.Abp.AspNetCore.Authentication.JwtBearer; + ... + typeof(AbpAspNetCoreAuthenticationJwtBearerModule), + typeof(AbpAccountWebIdentityServerModule), + ``` + + with + + ```csharp + using OpenIddict.Validation.AspNetCore; + ... + typeof(AbpAccountWebOpenIddictModule), + ``` + +- In the **MyApplicationBlazorModule.cs** add `PreConfigureServices` like below with your application name as the audience: + + ```csharp + public override void PreConfigureServices(ServiceConfigurationContext context) + { + PreConfigure(builder => + { + builder.AddValidation(options => + { + options.AddAudiences("MyApplication"); // Replace with your application name + options.UseLocalServer(); + options.UseAspNetCore(); + }); + }); + } + ``` + +- In the **MyApplicationBlazorModule.cs** `ConfigureServices` method, **replace the method call**: + + From `ConfigureAuthentication(context, configuration);` to `ConfigureAuthentication(context);` and update the method as: + + ```csharp + private void ConfigureAuthentication(ServiceConfigurationContext context) + { + context.Services.ForwardIdentityAuthenticationForBearer(OpenIddictValidationAspNetCoreDefaults.AuthenticationScheme); + } + ``` + +- In the **MyApplicationBlazorModule.cs** `OnApplicationInitialization` method, **replace the midware**: + + ```csharp + app.UseJwtTokenMiddleware(); + app.UseIdentityServer(); + ``` + + with + + ``` + app.UseAbpOpenIddictValidation(); + ``` + +## Blazor Project (Tiered Solution) + +- In the **MyApplicationWebModule.cs** update the `AddAbpOpenIdConnect` configurations: + + ```csharp + .AddAbpOpenIdConnect("oidc", options => + { + options.Authority = configuration["AuthServer:Authority"]; + options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); + options.ResponseType = OpenIdConnectResponseType.CodeIdToken; + + options.ClientId = configuration["AuthServer:ClientId"]; + options.ClientSecret = configuration["AuthServer:ClientSecret"]; + + options.SaveTokens = true; + options.GetClaimsFromUserInfoEndpoint = true; + + options.Scope.Add("roles"); // Replace "role" with "roles" + options.Scope.Add("email"); + options.Scope.Add("phone"); + options.Scope.Add("MyApplication"); + }); + ``` + + Replace **role** scope with **roles**. + +## IdentityServer + +This project is renamed to **AuthServer** after v6.0.0-rc1. You can also refactor and rename your project to *AuthServer* for easier updates in the future. + +- In **MyApplication.IdentityServer.csproj** replace **project references**: + + ```csharp + + ``` + + with + + ```csharp + + ``` + +- In **MyApplicationIdentityServerModule.cs** replace usings and **module dependencies**: + + ```csharp + typeof(AbpAccountWebIdentityServerModule), + ``` + + with + + ```csharp + typeof(AbpAccountWebOpenIddictModule), + ``` + +- In the **MyApplicationIdentityServerModule.cs** add `PreConfigureServices` like below with your application name as the audience: + + ```csharp + public override void PreConfigureServices(ServiceConfigurationContext context) + { + PreConfigure(builder => + { + builder.AddValidation(options => + { + options.AddAudiences("MyApplication"); // Replace with your application name + options.UseLocalServer(); + options.UseAspNetCore(); + }); + }); + } + ``` + +- In **MyApplicationIdentityServerModule.cs** `OnApplicationInitialization` method **remove IdentityServer midware**: + + ```csharp + app.UseIdentityServer(); + ``` + +## Http.Api.Host + +- In the **MyApplicationHttpApiHostModule.cs** `OnApplicationInitialization` method, delete `c.OAuthClientSecret(configuration["AuthServer:SwaggerClientSecret"]);` in `app.UseAbpSwaggerUI` options configurations which is no longer needed. + +- In `appsettings.json` delete **SwaggerClientSecret** from the *AuthServer* section like below: + + ```json + "AuthServer": { + "Authority": "https://localhost:44345", + "RequireHttpsMetadata": "false", + "SwaggerClientId": "MyApplication_Swagger" + }, + +## See Also + +* [OpenIddict Step-by-Step Guide](./OpenIddict-Step-by-Step.md)