A simple implementation of OAuth that includes the tenant_id
in the
OAuth2 endpoint, facilitating the Microsoft identity platform version 2. Apart
from the configurable tenant ID, this simply extends the OAuth implementation.
- author bvandgrift
- github bvandgrift/ueberauth_azure_ad
Originally forked in a hurry from swelhan/ueberauth_microsoft, with much gratitude.
Please see LICENSE for licensing details.
You can use this strategy by configuring it with your Azure AD tenant and secret information, then calling the local endpoints as follows:
-
Setup your application at the new Microsoft app registration portal.
-
Add
:ueberauth_azure_ad
to your list of dependencies inmix.exs
:def deps do [{:ueberauth_azure_ad, "~> 0.5"}] end
-
Add the strategy to your applications:
def application do [applications: [:ueberauth_azure_ad]] end
-
Add Microsoft to your Überauth configuration:
config :ueberauth, Ueberauth, providers: [ azure: {Ueberauth.Strategy.AzureAD, []} ]
-
Update your provider configuration:
config :ueberauth, Ueberauth.Strategy.AzureAD.OAuth, client_id: System.get_env("AZURE_CLIENT_ID"), client_secret: System.get_env("AZURE_CLIENT_SECRET"), tenant_id: System.get_env("AZURE_TENANT_ID")
-
Include the Überauth plug in your controller:
defmodule MyApp.AuthController do use MyApp.Web, :controller plug Ueberauth ... end
-
Create the request and callback routes if you haven't already:
scope "/auth", MyApp do pipe_through :browser get "/:provider", AuthController, :request get "/:provider/callback", AuthController, :callback end
-
Your controller needs to implement callbacks to deal with
Ueberauth.Auth
andUeberauth.Failure
responses.
For an example implementation see the Überauth Example application.
Depending on the configured url you can initial the request through:
/auth/azure
By default the scopes used are
- openid
- offline_access
- https://graph.microsoft.com/user.read
Note: at least one service scope is required in order for a token to be returned by the Microsoft endpoint
You can configure additional scopes to be used by passing the extra_scopes
option into the provider
config :ueberauth, Ueberauth,
providers: [
azure: {Ueberauth.Strategy.AzureAD, [extra_scopes: "https://graph.microsoft.com/calendars.read"]}
]