Git Product home page Git Product logo

Comments (6)

leastprivilege avatar leastprivilege commented on June 10, 2024

hm - the session is probably not populated at this point - that why there is nothing to return.

Why are basing the cookie lifetime on the existence of an access token?

from identitymodel.aspnetcore.

DaleyKD avatar DaleyKD commented on June 10, 2024

I was just using the example provided at:
https://github.com/IdentityServer/IdentityServer4/blob/master/samples/Clients/src/MvcAutomaticTokenManagement/Startup.cs

And the next one followed suit:
https://github.com/IdentityServer/IdentityServer4/blob/master/samples/Clients/src/MvcHybridAutomaticRefresh/Startup.cs

Except that one uses an early version of this repo's code, and it uses its own CookieAuthenticationEvents but it doesn't do a check for the user on the HttpContext.

from identitymodel.aspnetcore.

DaleyKD avatar DaleyKD commented on June 10, 2024

I had hoped that I could just add a new overload to IAccessTokenManagementService that looked like Task<string> GetUserAccessTokenAsync(ClaimsPrincipal principal, bool forceRenewal = false); . Then I'd use that principal in lieu of HttpContext.User .

However, when it got to var userToken = await _userTokenStore.GetTokenAsync(user); (where user is from the CookieValidatePrincipalContext.Principal), it just stopped debugging.

I can't look at it anymore this week due to the end of the sprint. I can try to look into it again in a week or so.

If you want more information, let me know.

In my client, I'm using ASP.NET Core Identity, and then using AddOpenIdConnect to connect to IdentityServer4 v3.0.2 and .NET Core 3.1.1.

from identitymodel.aspnetcore.

DaleyKD avatar DaleyKD commented on June 10, 2024

More info. It appears that the reason AuthenticationSessionUserTokenStore.GetTokenAsync is crashing is a StackOverflowException. When it calls await _contextAccessor.HttpContext.AuthenticateAsync();, it triggers the Cookie event ValidatePrincipal again. An infinite loop ensues.

from identitymodel.aspnetcore.

DaleyKD avatar DaleyKD commented on June 10, 2024

I used the code out of https://github.com/IdentityServer/IdentityServer4/tree/master/samples/Clients/src/MvcHybridAutomaticRefresh/AutomaticTokenManagement for today.

In order to get it to work, I had to set context.ShouldRenew = true; before the SignInAsync in AutomaticTokenManagementCookieEvents.

from identitymodel.aspnetcore.

github-actions avatar github-actions commented on June 10, 2024

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue.

from identitymodel.aspnetcore.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.