Base solution for your next web application
Open Closed

How can I enable both okta and auth0 for a tenant using openid #12204


User avatar
0
kansoftware created

I want to enable both okta and auth0 for a single tenant as some users may login through okta and some through auth0. I am having a multitenant application. Do I need to custom the code or there is a functionality in the base code. Could you please help me out how can I achieve that

Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)

145 Answer(s)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Can you reproduce the above case and share the Logs.txt file?

    [email protected]

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    Can you reproduce the above case and share the Logs.txt file?

    [email protected]

    Thanks.

    I don't think logs file will help you out, as I can't see any such error or logs related to this in logs file. what exactly you want to check? Also I believe when we are setting the options in custom class MyOpenIdChallengeResult we are not setting it tenant and it is getting override with the latest login tenant options.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    I will check the https://github.com/maliming/CDP-Base-Zero-13.0.0/ project with the tenant again

    Thanks.,

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    I will check the https://github.com/maliming/CDP-Base-Zero-13.0.0/ project with the tenant again

    Thanks.,

    Hi, were you able to find a solution for the issue?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    I checked, There is no problem with https://github.com/maliming/CDP-Base-Zero-13.0.0/

    Can you share the full code of your AccountController?

    [email protected]

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    I checked, There is no problem with https://github.com/maliming/CDP-Base-Zero-13.0.0/

    Can you share the full code of your AccountController?

    [email protected]

    Thanks.

    Did you tried with 2 different tenants and auth0 keys? The issue is its overriding the options.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Please share your code. I need to make sure the code is the same.

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    Please share your code. I need to make sure the code is the same.

    Thanks.

    Shared you over the email.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Can you also change the OpenIdConnectOptions in the Logout method?

    Just like https://github.com/maliming/CDP-Base-Zero-13.0.0/blob/master/src/CDP.Web.Mvc/Controllers/AccountController.cs#L301-L357

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    https://github.com/maliming/CDP-Base-Zero-13.0.0/blob/master/src/CDP.Web.Mvc/Controllers/AccountController.cs#L301-L357

    Ok I will try that but I believe it should not override the provider options when login in with 2 different tenants. Does the base code of dot net also does the same or it set the options tenant wise?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    You need to overwrite it when it is to be used.

    You can output more logs in the Logout method for troubleshooting.

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    You need to overwrite it when it is to be used.

    You can output more logs in the Logout method for troubleshooting.

    Thanks.

    Ok and the same thing zero does on login with the base code for openid options?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Yes, You need to overwrite it when it is to be used.

    Login. Logout.Challenge

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    Yes, You need to overwrite it when it is to be used.

    Login. Logout.Challenge

    Thanks.

    Another issue I am facing with the login code is, for one tenant I click on login button and it sets the options and redirect to the auth0 login screen, now for another tenant I clicked on login button and it sets the second tenant options and redirect to the auth0 login screen. After this when I try to login with first tenant it says - OpenIdConnectProtocolException: Message contains error: 'invalid_grant', error_description: 'Invalid authorization code', error_uri: 'error_uri is null'.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    Another issue I am facing with the login code is, for one tenant I click on login button and it sets the options and redirect to the auth0 login screen, now for another tenant I clicked on login button and it sets the second tenant options and redirect to the auth0 login screen. After this when I try to login with first tenant it says - OpenIdConnectProtocolException: Message contains error: 'invalid_grant', error_description: 'Invalid authorization code', error_uri: 'error_uri is null'.

    Can you reproduce in https://github.com/maliming/CDP-Base-Zero-13.0.0/blob/ ?

    Can you share all http requests&responses info?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    Another issue I am facing with the login code is, for one tenant I click on login button and it sets the options and redirect to the auth0 login screen, now for another tenant I clicked on login button and it sets the second tenant options and redirect to the auth0 login screen. After this when I try to login with first tenant it says - OpenIdConnectProtocolException: Message contains error: 'invalid_grant', error_description: 'Invalid authorization code', error_uri: 'error_uri is null'.

    Can you reproduce in https://github.com/maliming/CDP-Base-Zero-13.0.0/blob/ ?

    Can you share all http requests&responses info?

    I have shared the logs on email. Also will reproduce in the git code and let you know

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    I have shared the logs on email. Also I have reproduce and committed the code in the git repo. https://github.com/maliming/CDP-Base-Zero-13.0.0/commit/c69df1459996dd1b5e8ae6a181f03300c63d7826

    Steps to reproduce -

    1. Run application in 2 different browsers
    2. Tenant 1 - Click in OpenID Connect button on login screen
    3. Tenant 2 - Click in OpenID Connect button on login screen
    4. Tenant 1 - Enter the auth0 credentials ( sharing you the credentials on email) and after login the error comes.

    I believe its because of the same reason that options are getting override. And the same issue I am facing for the dot net zero code as well.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    Thanks. I will check your code asap.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    This commit will fix the problem. Can you test it?

    Thanks.

    https://github.com/maliming/CDP-Base-Zero-13.0.0/commit/b2e3b90f7b39c7ac769dbd501814e148ed1c7be5

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    This commit will fix the problem. Can you test it?

    Thanks.

    https://github.com/maliming/CDP-Base-Zero-13.0.0/commit/b2e3b90f7b39c7ac769dbd501814e148ed1c7be5

    I don't want to hardcode the auth0 keys in AbpOpenIdConnectHandler class. In the commit I did it just to reproduce the scenario. In my case it will set dynamic based on the keys stored in the database against tenant.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    You can get the current tenant ID in this method. So you can get the dynamic key in the database.

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    You can get the current tenant ID in this method. So you can get the dynamic key in the database.

    Thanks.

    Ok will try it. Can you explain what actually have you implemented for the fix?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    hi

    AbpOpenIdConnectHandler will change the OpenIdConnectOptions value for every login request.

    IOptionsMonitor<OpenIdConnectOptions> is a singleton service. so we need to change it every time.

    Thanks.

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    kansoftware created

    hi

    AbpOpenIdConnectHandler will change the OpenIdConnectOptions value for every login request.

    IOptionsMonitor<OpenIdConnectOptions> is a singleton service. so we need to change it every time.

    Thanks.

    And how does it get triggered on every login request?

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)
  • User Avatar
    0
    maliming created
    Support Team

    AbpOpenIdConnectHandler handles the callback for external login.

    Callback url is https://localhost/signin-oidc

    Markdown is supported
    Copy & paste or drag & drop images (max 30 MB per image)