diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs index b250e7b9..f231a383 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs @@ -154,14 +154,13 @@ public class EShopOnAbpPublicWebModule : AbpModule options.Scope.Add("phone"); options.Scope.Add("roles"); options.Scope.Add("offline_access"); - // Audiences couldn't be seeded -> TODO: Update when library is updated - // options.Scope.Add("AccountService"); - // options.Scope.Add("AdministrationService"); - // options.Scope.Add("BasketService"); - // options.Scope.Add("CatalogService"); - // options.Scope.Add("PaymentService"); - // options.Scope.Add("OrderingService"); - // options.Scope.Add("CmskitService"); + + options.Scope.Add("AdministrationService"); + options.Scope.Add("BasketService"); + options.Scope.Add("CatalogService"); + options.Scope.Add("PaymentService"); + options.Scope.Add("OrderingService"); + options.Scope.Add("CmskitService"); options.SaveTokens = true; //Token response type, will sometimes need to be changed to IdToken, depending on config. diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj b/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj index f7f9c1ba..47d14f09 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/EShopOnAbp.Keycloak.DbMigrator.csproj @@ -8,12 +8,11 @@ - + - diff --git a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs index 32aff192..80051883 100644 --- a/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs +++ b/shared/EShopOnAbp.Keycloak.DbMigrator/KeycloakDataSeeder.cs @@ -43,7 +43,6 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency private async Task CreateClientScopesAsync() { - await CreateScopeAsync("AccountService"); await CreateScopeAsync("AdministrationService"); await CreateScopeAsync("IdentityService"); await CreateScopeAsync("BasketService"); @@ -78,16 +77,11 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency Name = scopeName, Protocol = "openid-connect", _ProtocolMapper = "oidc-audience-mapper", - // Config = new Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // { - // { "id.token.claim", "false" }, - // { "access.token.claim", "true" }, - // { "included.custom.audience", scopeName } - // } - Config = new Config() // This should be dictionary -> Outdated library + Config = new Dictionary() //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged { - AccessTokenClaim = "true", - IdTokenClaim = "false" + { "id.token.claim", "false" }, + { "access.token.claim", "true" }, + { "included.custom.audience", scopeName } } } } @@ -133,15 +127,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, webClient); - //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // await AddOptionalClientScopesAsync( - // "PublicWeb", - // new List - // { - // "AdministrationService", "IdentityService", "BasketService", "CatalogService", - // "OrderingService", "PaymentService", "CmskitService" - // } - // ); + await AddOptionalClientScopesAsync( + "PublicWeb", + new List + { + "AdministrationService", "IdentityService", "BasketService", "CatalogService", + "OrderingService", "PaymentService", "CmskitService" + } + ); } } @@ -219,15 +212,14 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency await _keycloakClient.CreateClientAsync(_keycloakOptions.RealmName, publicWebClient); - //TODO: Update when //https://github.com/AnderssonPeter/Keycloak.Net/pull/5 is merged - // await AddOptionalClientScopesAsync( - // "PublicWeb", - // new List - // { - // "AdministrationService", "IdentityService", "BasketService", "CatalogService", - // "OrderingService", "PaymentService", "CmskitService" - // } - // ); + await AddOptionalClientScopesAsync( + "PublicWeb", + new List + { + "AdministrationService", "IdentityService", "BasketService", "CatalogService", + "OrderingService", "PaymentService", "CmskitService" + } + ); } } @@ -264,8 +256,6 @@ public class KeyCloakDataSeeder : IDataSeedContributor, ITransientDependency var adminUser = users.FirstOrDefault(); if (adminUser == null) { - _logger.LogError( - "Keycloak admin user is not provided, check if KEYCLOAK_ADMIN environment variable is passed properly."); throw new Exception( "Keycloak admin user is not provided, check if KEYCLOAK_ADMIN environment variable is passed properly."); } diff --git a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs index 0cc48603..f87c63f4 100644 --- a/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs +++ b/shared/EShopOnAbp.Shared.Hosting.Microservices/JwtBearerConfigurationHelper.cs @@ -20,10 +20,6 @@ public static class JwtBearerConfigurationHelper options.Authority = configuration["AuthServer:Authority"]; options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); options.Audience = audience; - options.TokenValidationParameters = new TokenValidationParameters() - { - ValidateAudience = false //Disabled since seeding audience is not possible with the current keycloak.net library version - }; }); } } \ No newline at end of file