-
Notifications
You must be signed in to change notification settings - Fork 8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Error authenticating with Azure AD B2C OAuth2 provider #1757
Comments
As a workaround I've had to temporarily change |
Hey @jjgriff93, thanks for a detailed description. You are right, currently only two OAuth2 response types are supported out of the box - The reason why you are getting the error after providing a custom We should to think about a way to allow extension of this functoinality, but currently I can see two possible workarounds:
|
Thanks @nnixaa , that first workaround has worked perfectly. Have replied to you on the other related issue re the redirecting, so we can close this one off. Thanks again! |
I have just posted another issue with the same error. It appears this fix works only in the development build. The error recurs when switched into production mode. Any ideas why this might be? |
I believe jjgriff93's overwrite of the enum value is not reassigning the value when in production mode. I have tried removing buildOptimizer from production build as this has had previous problems affecting enums. However, this has no effect in this case and still get the same error as above. |
Interesting @stubbsy345 I've just tested this and get the same behaviour, not working with |
Hey @jjgriff93, could you post the error? |
@nnixaa it is exactly the same as the error in the original post on this thread. It appears your solution for overwriting the enum does not work when built in production. |
Issue type
I'm submitting a ... (check one with "x")
Issue description
Current behavior:
I'm trying to implement Azure AD B2C as an authentication provider in the ngx-admin starter kit. I've followed the docs for implementing an OAuth2 provider, and have created an authentication strategy with all the required fields.
All goes well when clicking the login button, I am directed to the microsoft log in, however after signing in and redirected back to my app, I get 'This application does not have sufficient permissions against this web resource'.
After some testing, I've found that the reason for this is because Azure AD B2C expects the
responseType
parameter to haveid_token
instead oftoken
in line with OAuth2 authentication standards. However, following the Nebular docs, for theresponseType
parameter in the authentication strategy, we're told to putNbOAuth2ResponseType.TOKEN
. After checking what this substitutes in, I can see that this provides a string oftoken
, notid_token
, which is causing my issue.I can't see any way to override this however. When I try and replace
NbOAuth2ResponseType.TOKEN
with'id_token'
and testing, the login button will no longer work, and in the JavaScript console I get:Expected behavior:
Not receiving an error after clicking the login button, or having the option for
NbOAuth2ResponseType.IDTOKEN
in the nebular/auth library.Steps to reproduce:
core.module.ts
like so:The text was updated successfully, but these errors were encountered: