Added a custom DelegatingHandler, SenderAuthCookieHandler, to forward the browser's Cookie header to outgoing HttpClient requests in Blazor Server. Registered the handler as a transient service and integrated it into the named HttpClient pipeline for internal API calls. This enables Blazor Server components to make authenticated API calls using cookie-based JWT authentication (AuthScheme.Sender).
34 lines
1.5 KiB
C#
34 lines
1.5 KiB
C#
namespace EnvelopeGenerator.Server.Handlers;
|
|
|
|
/// <summary>
|
|
/// A <see cref="DelegatingHandler"/> that forwards the incoming HTTP request's
|
|
/// <c>Cookie</c> header to all outgoing <see cref="System.Net.Http.HttpClient"/> calls
|
|
/// made by Blazor Server components.
|
|
///
|
|
/// Problem it solves:
|
|
/// Blazor Server runs on the server process. When a component calls an API endpoint
|
|
/// that requires cookie-based JWT authentication (AuthScheme.Sender), the HttpClient
|
|
/// does not automatically include the browser's cookies — those only travel with
|
|
/// browser-initiated requests. This handler copies the <c>Cookie</c> header from the
|
|
/// current <see cref="IHttpContextAccessor.HttpContext"/> into every outgoing request
|
|
/// so that the API's JwtBearer <c>OnMessageReceived</c> callback can extract the token.
|
|
///
|
|
/// Thread safety:
|
|
/// The handler is registered as Transient and is resolved per-request by the
|
|
/// IHttpClientFactory pipeline, so there is no shared state between requests.
|
|
/// </summary>
|
|
public class SenderAuthCookieHandler(IHttpContextAccessor httpContextAccessor) : DelegatingHandler
|
|
{
|
|
protected override Task<HttpResponseMessage> SendAsync(
|
|
HttpRequestMessage request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
var cookieHeader = httpContextAccessor.HttpContext?.Request.Headers["Cookie"].ToString();
|
|
|
|
if (!string.IsNullOrWhiteSpace(cookieHeader))
|
|
request.Headers.TryAddWithoutValidation("Cookie", cookieHeader);
|
|
|
|
return base.SendAsync(request, cancellationToken);
|
|
}
|
|
}
|