Browse Source

Implement native grant_type=client_credentials support

pull/12/merge
Kévin Chalet 11 years ago
parent
commit
d296738afe
  1. 23
      src/OpenIddict.Core/OpenIddictProvider.cs

23
src/OpenIddict.Core/OpenIddictProvider.cs

@ -197,13 +197,12 @@ namespace OpenIddict {
// Note: OpenIdConnectServerHandler supports authorization code, refresh token, client credentials // Note: OpenIdConnectServerHandler supports authorization code, refresh token, client credentials
// and resource owner password credentials grant types but this authorization server uses a stricter policy // and resource owner password credentials grant types but this authorization server uses a stricter policy
// rejecting the last one. You may consider relaxing it to support the client credentials grant types. // rejecting the last one. You may consider relaxing it to support the client credentials grant types.
if (!context.Request.IsAuthorizationCodeGrantType() && if (!context.Request.IsAuthorizationCodeGrantType() && !context.Request.IsRefreshTokenGrantType() &&
!context.Request.IsRefreshTokenGrantType() && !context.Request.IsPasswordGrantType() && !context.Request.IsClientCredentialsGrantType()) {
!context.Request.IsPasswordGrantType()) {
context.Rejected( context.Rejected(
error: OpenIdConnectConstants.Errors.UnsupportedGrantType, error: OpenIdConnectConstants.Errors.UnsupportedGrantType,
description: "Only authorization code and refresh token grant types " + description: "Only authorization code, refresh token, client credentials " +
"are accepted by this authorization server."); "and password grants are accepted by this authorization server.");
} }
return Task.FromResult<object>(null); return Task.FromResult<object>(null);
@ -309,6 +308,20 @@ namespace OpenIddict {
} }
} }
public override async Task GrantClientCredentials([NotNull] GrantClientCredentialsContext context) {
var manager = context.HttpContext.RequestServices.GetRequiredService<OpenIddictManager<TUser, TApplication>>();
// Retrieve the application details corresponding to the requested client_id.
var application = await manager.FindApplicationByIdAsync(context.ClientId);
Debug.Assert(application != null);
var identity = new ClaimsIdentity(context.Options.AuthenticationScheme);
identity.AddClaim(ClaimTypes.NameIdentifier, context.ClientId);
identity.AddClaim(ClaimTypes.Name, await manager.GetDisplayNameAsync(application));
context.Validated(new ClaimsPrincipal(identity));
}
public override async Task GrantResourceOwnerCredentials([NotNull] GrantResourceOwnerCredentialsContext context) { public override async Task GrantResourceOwnerCredentials([NotNull] GrantResourceOwnerCredentialsContext context) {
var manager = context.HttpContext.RequestServices.GetRequiredService<OpenIddictManager<TUser, TApplication>>(); var manager = context.HttpContext.RequestServices.GetRequiredService<OpenIddictManager<TUser, TApplication>>();

Loading…
Cancel
Save