mirror of
https://github.com/wiremock/WireMock.Net.git
synced 2026-09-04 00:47:17 +02:00
Unauthorized (401) error when calling the admin API with version 2 Azure AAD tokens. #688
Closed
opened 2025-12-29 08:32:31 +01:00 by adam
·
16 comments
No Branch/Tag Specified
master
1341-mapping-json
stef-aspire-tests-updates
bug/973-TinyMapper
bug/1149-AppendGuidToSavedMappingFile
feature/1150-DockerImageVersion
61
stef-1108
stef-1097
stef-1083-MessageOptions_Type_Conflict
stef-1062-logger
stef-IgnoreOpenApiErrors
stef-928-TypeLoadException-FluentAssertions-net472
nunit
stef-849
stef-847-regex-questionmark
http_verb
WireMockServerContext
webapp
ai
CommandLineArgumentsParser
2.15.0
2.14.0
2.13.0
2.12.0
2.11.0
2.10.0
2.9.0
2.8.0
2.7.0
2.6.0
2.5.0
2.4.0
2.3.0
2.2.0
2.1.0
2.0.0
1.25.0
1.24.0
1.23.0
1.22.0
1.21.0
1.20.0
1.19.0
1.18.0
1.17.0
1.16.0
1.15.0
1.14.0
1.13.0
1.12.0
1.11.2
1.11.0
1.10.1
1.10.0
1.9.1
1.9.0
1.8.18
1.8.17
1.8.16
1.8.15
1.8.14
1.8.13
1.8.12
1.8.11
1.8.10
1.8.9
1.8.8
1.8.7
1.8.6
1.8.5
1.8.3
1.8.2
1.8.1
1.8.0
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0
1.6.12
1.6.11
1.6.10
1.6.9
1.6.8
1.6.7
1.6.6
1.6.5
1.6.4
1.6.3
1.6.2
1.6.1
1.6.0
1.5.62
1.5.61
1.5.60
1.5.59
1.5.58
1.5.57
1.5.56
1.5.55
1.5.54
1.5.53
1.5.52
1.5.51
1.5.50
1.5.49
1.5.48
1.5.47
1.5.46
1.5.45
1.5.44
1.5.43
1.5.42
1.5.41
1.5.40
1.5.39
1.5.38
1.5.37
1.5.36
1.5.35
1.5.34
1.5.33
1.5.32
1.5.31
1.5.30
1.5.29
1.5.28
1.5.27
1.5.26
1.5.25
1.5.24
1.5.23
1.5.22
1.5.21
1.5.20
1.5.19
1.5.18
1.5.17
1.5.16
1.5.15
1.5.14
1.5.13
1.5.12
1.5.11
1.5.10
1.5.9
1.5.8
1.5.7
1.5.6
1.5.5
1.5.4
1.5.3
1.5.2
1.5.1
1.5.0
1.4.43
1.4.42
1.4.41
1.4.40
1.4.39
1.4.38
1.4.37
1.4.36
1.4.35
1.4.34
1.4.33
1.4.32
1.4.31
1.4.30
1.4.29
1.4.28
1.4.27
1.4.26
1.4.25
1.4.24
1.4.23
1.4.22
1.4.21
1.4.20
1.4.19
1.4.18
1.4.17
1.4.16
1.4.15
1.4.14
1.4.13
1.4.12
1.4.11
1.4.10
1.4.9
1.4.8
1.4.7
1.4.6
1.4.5
1.4.4
1.4.3
1.4.2
1.4.1
1.4.0
1.3.10
1.3.9
1.3.8
1.3.6
1.3.5
1.3.4
1.3.3
1.3.2
1.3.1
1.3.0
1.2.18
1.2.17
1.2.16
1.2.15
1.2.14
1.2.13
1.2.12
1.2.11.0
1.2.10
1.2.9.0
1.2.8.0
1.2.7.0
1.2.6.0
1.2.5.0
1.2.4.0
1.2.3.0
1.2.2.0
1.2.1.0
1.2.0.0
1.1.10
1.1.9.0
1.1.8.0
1.1.7.0
1.1.6.0
1.1.5.0
1.1.3.0
1.1.2.0
1.1.1.0
1.1.0.0
1.0.43.0
1.0.42.0
1.0.41.0
1.0.40.0
1.0.39.0
1.0.38.0
1.0.37.0
1.0.36.0
1.0.35.0
1.0.34.0
1.0.33.0
1.0.32.0
1.0.31.0
1.0.29.0
1.0.28.0
1.0.25.0
1.0.24.0
1.0.23.0
1.0.22.0
1.0.21.0
1.0.20.0
1.0.19.0
1.0.18.0
1.0.17.0
1.0.16.0
1.0.15.0
1.0.14.0
1.0.13.0
1.0.12.0
1.0.11.0
1.0.10.0
1.0.9.0
1.0.8.0
1.0.7.0
1.0.6.1
1.0.6
1.0.5
1.0.4.21
1.0.4.20
1.0.4.19
1.0.4.18
1.0.4.17
1.0.4.16
1.0.4.15
1.0.4.14
1.0.4.13
1.0.4.12
1.0.4.11
1.0.4.10
1.0.4.9
1.0.4.8
1.0.4.7
1.0.4.6
1.0.4.5
1.0.4.4
1.0.4.3
1.0.4.2
1.0.4.1
1.0.4.0
1.0.3.20
1.0.3.19
1.0.3.18
1.0.3.17
1.0.3.16
1.0.3.15
1.0.3.14
1.0.3.13
1.0.3.12
1.0.3.11
1.0.3.10
1.0.3.9
1.0.3.8
1.0.3.7
1.0.3.6
1.0.3.5
1.0.3.4
1.0.3.3
1.0.3.2
1.0.3.1
1.0.3.0
1.0.2.13
1.0.2.12
1.0.2.11
1.0.2.10
1.0.2.9
1.0.2.8
1.0.2.7
1.0.2.6
1.0.2.5
1.0.2.4
1.0.2.1
1.0.2.0
1.0.1.5
1.0.1.3
1.0.1.2
1.0.1.1
1.0.0.0
Milestone
No items
No Milestone
Projects
Clear projects
No projects
Assignees
adam (Adam Melkus)
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/WireMock.Net#688
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Originally created by @AchoArnold on GitHub (Apr 29, 2025).
Originally assigned to: @StefH on GitHub.
Describe the bug
401When it is configured to use version 2 of the AAD token. This happens because of the validation code here https://github.com/WireMock-Net/WireMock.Net/blob/e7310fbc7b2930be099e65b5673c7846576496f7/src/WireMock.Net/Authentication/AzureADAuthenticationMatcher.cs#L61The
issuwerfromhttps://login.microsoftonline.com/{tennantID}/.well-known/openid-configurationis given ashttps://sts.windows.net/{tennantID}/but when you decode a v2 AAD token using jwt.ms, the issuer is set ashttps://login.microsoftonline.com/{tennantID}/v2.0And the recommendation is that instead of comparing the entire string, you should only compare that the tennants match. The identity model even has a helper method for validating the issuwer https://github.com/AzureAD/microsoft-identity-web/blob/36fb5f555638787823a89e89c67f17d6a10006ed/tools/CrossPlatformValidator/CrossPlatformValidation/CrossPlatformValidation/RequestValidator.cs#L42Expected behavior:
I can make wiremock admin API requests with with AAD version 2 tokens
Test to reproduce
/__admin/requestsand you'll get 401 instead of 200Other related info
Provide additional information if any.
@StefH commented on GitHub (Apr 30, 2025):
@AchoArnold
I did update some code, but was not able to test it. (https://github.com/WireMock-Net/WireMock.Net/pull/1288)
Can you test latest preview
1.8.0-ci-19960(https://github.com/WireMock-Net/WireMock.Net/wiki/MyGet-preview-versions)
@StefH commented on GitHub (May 2, 2025):
@AchoArnold
I did update some code, but was not able to test it. (https://github.com/WireMock-Net/WireMock.Net/pull/1288)
Can you test latest preview
1.8.0-ci-19960(https://github.com/WireMock-Net/WireMock.Net/wiki/MyGet-preview-versions)
@AchoArnold commented on GitHub (May 2, 2025):
Hello @StefH
Thanks for the fast response, I'll be able to test it out on Monday next week.
@AchoArnold commented on GitHub (May 2, 2025):
Hello @StefH
I installed the nuget source but I can't see this speicifc CI version
@AchoArnold commented on GitHub (May 2, 2025):
@StefH I downloaded the nupkg from here https://dev.azure.com/stef/WireMock.Net/_build/results?buildId=9960&view=artifacts&pathAsName=false&type=publishedArtifacts and ran the specific version.
I can confirm that the bug is now fixed I'm authenticating with 200
@StefH commented on GitHub (May 2, 2025):
That's good news.
Would you be so kind to share the postman request or collection (without any traceable credentials to your system). I cannot find my own test anymore.
And can you also share the C# code for this? (I also cannot find any example code anymore..)
@AchoArnold commented on GitHub (May 2, 2025):
Hello @StefH , I don't have any postman but I can send the instructions here.
To get v2.0 AAD token you need to modify the
Manifestof your AAD app registration by following the instructions here https://docs.azure.cn/en-us/entra/identity-platform/scenario-protected-web-api-app-registration#accepted-token-versionYou can then get the token using this CURL command
Once you obtain the token you can verify that it is version 2 using this website https://jwt.ms, I start the wiremock server. I'm using the
WireMock.Net.StandAlonepackage.And then I make a
GETrequest to{WiremockServerURL}/__admin/requestswith theBearer AadTokenset in theAuthorizationheader and 200 for success 401 for authentication errors.@AchoArnold commented on GitHub (May 2, 2025):
@StefH I just did a regression test and this new version of the wiremock.net package doesn't authenticate when I use a
ver1.0AAD token@StefH commented on GitHub (May 2, 2025):
@AchoArnold
I did a quick test for V1.
And the bearer token is decoded as:
And calling an /__admin endpoint in WireMock.Net works fine.
Can you double check how the issuer looks on your side?
@AchoArnold commented on GitHub (May 2, 2025):
@StefH I don't think the problem is the issuer but the issue is with
Audienceinv1theaudisapi://UUIDbut in v2 theaudisUUIDSo this can be fixed at the config level i.e
instead of
A few suggestions,
Thanks.
@StefH commented on GitHub (May 2, 2025):
1⃣
For C# code I do:
And I do a post to URL:
https://login.microsoftonline.com/<TENANT>/oauth2/tokenWith values:

And result is:
When I use this access_token in a GET request to
http://localhost:9091/__admin/settings(when running in debug step).All is fine.
(A NuGet version should be WireMock.1.8.1-ci-19970)
2⃣
Yes I checked that link, however, I thought I needed to include another NuGet for that logic, so I just build the logic myself.
3⃣
I think when you get the logging from wiremock, the exception should be present.
@AchoArnold commented on GitHub (May 5, 2025):
@StefH Any tips on how we can do this? I use the
WiremockConsoleLoggerand when there is an error this is the only log line which I see https://github.com/WireMock-Net/WireMock.Net/blob/cfc13b2449b275d074b967c0abf5ebcf3be6ef08/src/WireMock.Net/Owin/WireMockMiddleware.cs#L141 I don't see the results of the token validator to see if the problem is with the resource, issuer, or some other problem I had to reverse engineer the code to discover that the reason for authentication failures was because of issuer mismatch.Perhaps we can log
matchResult.Exception@StefH commented on GitHub (May 6, 2025):
@AchoArnold
Exception has been added to the logging.
Please test preview :
1.8.2-ci-19997@AchoArnold commented on GitHub (May 6, 2025):
Thanks @StefH Now the error is available in the logs.
@StefH commented on GitHub (May 6, 2025):
@AchoArnold
You need to use the correct audience in the setting I guess?
@AchoArnold commented on GitHub (May 6, 2025):
@StefH I was configured the
audiencewrongly on purpose to test that theExceptionlogging now works. And I can confirm that it works.Thanks.