0
gtc created
Markdown is supported
Copy & paste or drag & drop images (max 30 MB per image)
1 Answer(s)
-
0
Hi @gtc
In ASP.NET Zero v14, MSAL is integrated for OpenID Connect / Entra Id MSAL requires HTTPS, because it depends on
window.crypto.subtle(the Web Crypto API), which is only available in secure contexts.Make sure your production site runs under HTTPS.
In IIS:
- Add an HTTPS binding for your site.
- Use a valid certificate (self-signed for test, trusted one for production).
- Redirect HTTP → HTTPS.
In
web.config, you can add:<rewrite> <rules> <rule name="Redirect to HTTPS" stopProcessing="true"> <match url="(.*)" ignoreCase="false" /> <conditions> <add input="{HTTPS}" pattern="off" ignoreCase="true" /> </conditions> <action type="Redirect" url="https://{HTTP_HOST}/{R:1}" redirectType="Permanent" /> </rule> </rules> </rewrite>Even if the IIS redirect sends the user to the correct address (HTTPS), it is still necessary to update the
appconfig.production.jsonfile, which tells the Angular app where to make API requests.In the
src/assets/appconfig.production.jsonfile, make sure the URLs start withhttps://:{ "remoteServiceBaseUrl": "https://yourdomain.com", "appBaseUrl": "https://yourdomain.com", // ... }Markdown is supportedCopy & paste or drag & drop images (max 30 MB per image)
