Class ExternalController
- Namespace
- ProjectTemplate.Web.Controllers
- Assembly
- ProjectTemplate.Web.dll
Provides controller actions for initiating external authentication challenges using configured authentication schemes.
public sealed class ExternalController : Controller, IActionFilter, IAsyncActionFilter, IFilterMetadata, IDisposable
- Inheritance
-
ExternalController
- Implements
- Inherited Members
Remarks
This controller is intended for use with external authentication providers such as OAuth or OpenID Connect. It ensures that only local return URLs are accepted to mitigate open redirect vulnerabilities. The controller should be used in scenarios where users need to authenticate via third-party identity providers.
Constructors
ExternalController(IAuthenticationSchemeProvider)
Provides controller actions for initiating external authentication challenges using configured authentication schemes.
public ExternalController(IAuthenticationSchemeProvider schemeProvider)
Parameters
schemeProviderIAuthenticationSchemeProviderThe authentication scheme provider used to retrieve available external authentication schemes. Cannot be null.
Remarks
This controller is intended for use with external authentication providers such as OAuth or OpenID Connect. It ensures that only local return URLs are accepted to mitigate open redirect vulnerabilities. The controller should be used in scenarios where users need to authenticate via third-party identity providers.
Methods
Challenge(string, string?)
Initiates an external authentication challenge using the specified provider.
[HttpGet("/External/Challenge")]
[AllowAnonymous]
public Task<IActionResult> Challenge(string provider, string? returnUrl = null)
Parameters
providerstringThe name of the external authentication provider to use. Cannot be null, empty, or whitespace.
returnUrlstringThe URL to redirect the user to after successful authentication. If null or empty, defaults to the application's root ('/'). Must be a local URL.
Returns
- Task<IActionResult>
An IActionResult that initiates the external authentication challenge or returns a BadRequest result if the input is invalid.
Remarks
This method is typically used to start an OAuth or other external login flow. Only local return URLs are permitted to prevent open redirect vulnerabilities.