Identityserver4: Control resource actions access by scope

Created on 31 Aug 2016  路  5Comments  路  Source: IdentityServer/IdentityServer4

Hi!
Is there any way I can specify that, for instance, a

  • GET http:/myserver/mypath requires scope X and
  • GET http:/myserver/myOtherpath requires scope Y
    ?
    Is there some scope attribute or can I access that stuff from within the controller?
question

Most helpful comment

You'd have to build that yourself. You might be able to use the new policy based authorization: https://docs.asp.net/en/latest/security/authorization/claims.html

All 5 comments

You'd have to build that yourself. You might be able to use the new policy based authorization: https://docs.asp.net/en/latest/security/authorization/claims.html

Thanks a lot!
That's it.

What is the point of AllowedScopes if you can't limit controllers to scopes without writing another framework? Please someone tell me.

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

Was this page helpful?
0 / 5 - 0 ratings