© 2026 Hedgehog Software, LLC

TwitterGitHubDiscord
More
CommunitiesDocsAboutTermsPrivacy
Search
Star
Setup for Free
C#C
C#•3y ago•
75 replies
S-IERRA

❔ ASP.NET always validates invalid JWT

I have a custom configuration for Asp.net where the JWT Token is stored in an http-only cookie, because of this there is 1 method in specific that is always returning 200 no matter if there is no actual JWT attached

    public static void RegisterAuthorization(this IServiceCollection serviceCollection, IConfiguration configuration)
    {
        var jwtConfig = configuration.GetSection("Jwt").Get<JwtConfig>()!;
        serviceCollection.Configure<JwtConfig>(configuration.GetSection("Jwt"));

        serviceCollection.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
            .AddJwtBearer(options =>
            {   
                options.RequireHttpsMetadata = false;
                options.SaveToken = true;
                options.TokenValidationParameters = new TokenValidationParameters()
                {
                    ValidateIssuer = true,
                    ValidateAudience = true,
                    ValidAudience = jwtConfig.Audience,
                    ValidIssuer = jwtConfig.Issuer,
                    IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(jwtConfig.Key))
                };
                
                options.Events = new JwtBearerEvents
                {
                    OnMessageReceived = context =>
                    {
                        context.Token = context.Request.Cookies["JwtToken"];

                        return Task.CompletedTask;
                    }
                };
            });
    
        serviceCollection.AddAuthorization(options =>
        {
            options.AddPolicy(NumixAuthPolicy.Admin.ToString(), policy => 
                policy.RequireClaim(ClaimTypes.Role, NumixRole.Administrator.ToString()));
        });
    
        serviceCollection.AddScoped(typeof(IAuthenticatorService), typeof(Authenticate));
    }
    public static void RegisterAuthorization(this IServiceCollection serviceCollection, IConfiguration configuration)
    {
        var jwtConfig = configuration.GetSection("Jwt").Get<JwtConfig>()!;
        serviceCollection.Configure<JwtConfig>(configuration.GetSection("Jwt"));

        serviceCollection.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
            .AddJwtBearer(options =>
            {   
                options.RequireHttpsMetadata = false;
                options.SaveToken = true;
                options.TokenValidationParameters = new TokenValidationParameters()
                {
                    ValidateIssuer = true,
                    ValidateAudience = true,
                    ValidAudience = jwtConfig.Audience,
                    ValidIssuer = jwtConfig.Issuer,
                    IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(jwtConfig.Key))
                };
                
                options.Events = new JwtBearerEvents
                {
                    OnMessageReceived = context =>
                    {
                        context.Token = context.Request.Cookies["JwtToken"];

                        return Task.CompletedTask;
                    }
                };
            });
    
        serviceCollection.AddAuthorization(options =>
        {
            options.AddPolicy(NumixAuthPolicy.Admin.ToString(), policy => 
                policy.RequireClaim(ClaimTypes.Role, NumixRole.Administrator.ToString()));
        });
    
        serviceCollection.AddScoped(typeof(IAuthenticatorService), typeof(Authenticate));
    }
C# banner
C#Join
We are a programming server aimed at coders discussing everything related to C# (CSharp) and .NET.
61,871Members
Resources
Was this page helpful?

Similar Threads

Recent Announcements

Similar Threads

ASP .NET Core JWT Authentication, Bearer error="invalid_token"
C#CC# / help
3y ago
ASP.Net IActionResult always returns Ok
C#CC# / help
2y ago
ASP .NET 7 - Testing a JWT Token Generator
C#CC# / help
3y ago
❔ Converting ASP.NET 6 to ASP.NET 5
C#CC# / help
4y ago
Next page