Table of Contents

Class ExternalController

Namespace
ProjectTemplate.Web.Controllers
Assembly
ProjectTemplate.Web.dll

Provides controller actions for initiating external authentication challenges using configured authentication schemes.

public sealed class ExternalController : Controller, IActionFilter, IAsyncActionFilter, IFilterMetadata, IDisposable
Inheritance
ExternalController
Implements
Inherited Members

Remarks

This controller is intended for use with external authentication providers such as OAuth or OpenID Connect. It ensures that only local return URLs are accepted to mitigate open redirect vulnerabilities. The controller should be used in scenarios where users need to authenticate via third-party identity providers.

Constructors

ExternalController(IAuthenticationSchemeProvider)

Provides controller actions for initiating external authentication challenges using configured authentication schemes.

public ExternalController(IAuthenticationSchemeProvider schemeProvider)

Parameters

schemeProvider IAuthenticationSchemeProvider

The authentication scheme provider used to retrieve available external authentication schemes. Cannot be null.

Remarks

This controller is intended for use with external authentication providers such as OAuth or OpenID Connect. It ensures that only local return URLs are accepted to mitigate open redirect vulnerabilities. The controller should be used in scenarios where users need to authenticate via third-party identity providers.

Methods

Challenge(string, string?)

Initiates an external authentication challenge using the specified provider.

[HttpGet("/External/Challenge")]
[AllowAnonymous]
public Task<IActionResult> Challenge(string provider, string? returnUrl = null)

Parameters

provider string

The name of the external authentication provider to use. Cannot be null, empty, or whitespace.

returnUrl string

The URL to redirect the user to after successful authentication. If null or empty, defaults to the application's root ('/'). Must be a local URL.

Returns

Task<IActionResult>

An IActionResult that initiates the external authentication challenge or returns a BadRequest result if the input is invalid.

Remarks

This method is typically used to start an OAuth or other external login flow. Only local return URLs are permitted to prevent open redirect vulnerabilities.