使用两个 URL 使用 Azure AD 进行单点登录

cuo*_*gle 2 asp.net-mvc single-sign-on owin azure-active-directory openid-connect

假设我有 2 个 url 指向一个网站,只需使用站点绑定,例如:

productname1.company.com
productname2.company.com
Run Code Online (Sandbox Code Playgroud)

我们的 Web 应用程序单点登录到 Azure Active Directory,并且在 Azure 应用程序配置中,我放置了:

productname1.company.com
Run Code Online (Sandbox Code Playgroud)

对于登录 URL 和回复 URL:

在此输入图像描述

如果用户来到productname1.company.com,Azure 单点登录身份验证工作正常。

但如果用户来了productname2.company.com,它根本不起作用并重定向到 的登录页面productname1.company.com。

如何配置才能使其与productname2.company.comAzure AD 一起使用,我正在使用 OWIN OpenIdConnect 进行单点登录。

Ben*_*enV 5

您可以添加productname2.company.com第二个回复 URL,然后让您的应用在重定向到 AAD 时指定适当的回复 URL。

您可以在用于配置 OWIN OpenID Connect 的RedirectToIdentityProvider通知中执行此操作。OpenIdConnectAuthenticationOptions

app.UseOpenIdConnectAuthentication(
   new OpenIdConnectAuthenticationOptions
   {
      Notifications = new OpenIdConnectAuthenticationNotifications()
      {
         RedirectToIdentityProvider = (context) =>
           {
              // This ensures that the address used for sign in and sign out is picked up dynamically from the request
              // this allows you to deploy your app (to Azure Web Sites, for example) without having to change settings
              // Remember that the base URL of the address used here must be defined as a Redirect URI in Ping beforehand.
              string appBaseUrl = context.Request.Scheme + "://" + context.Request.Host + context.Request.PathBase;
              string currentUrl = context.Request.Scheme + "://" + context.Request.Host + context.Request.Path;
              context.ProtocolMessage.RedirectUri = currentUrl;
              context.ProtocolMessage.PostLogoutRedirectUri = appBaseUrl;
           }
      }
   }
Run Code Online (Sandbox Code Playgroud)