#Azure Active Directory OIDC Web Sample
This Node.js app will give you with a quick and easy way to set up a Web application in node.js with Express using OpenID Connect. The sample server included in the download are designed to run on any platform.
We've released all of the source code for this example in GitHub under an MIT license, so feel free to clone (or even better, fork!) and provide feedback on the forums.
Getting started with the sample is easy. It is configured to run out of the box with minimal setup.
If you don't have an Azure AD B2C Tenant yet, please create one.
Next let's register a web application in your tenant.
-
In the main page of your tenant, click
Manage B2C settings
, and you will be redirected to the settings page. -
Click
Applications
, then clickAdd
. Enter a name like 'my_b2c_app', and switch theWeb App / Web API
option to yes. After that, enter 'http://localhost:3000/auth/openid/return' into theReply URL
field. Then clickGenerate key
to generate a app key, and save it somewhere. This app key is the client secret of your application. Now clickCreate
button to finish registration. -
Click the application you just created, copy the
Application ID
field and save it somewhere. This value is the clientID of your application. -
Now let's add some policies we will use for this sample. In the setting page, add a sign-in policy, a sign-up poligy, a profile-editing policy and a password-reset policy. When you add the policies, use the names 'signin', 'signup', 'updateprofile' and 'resetpassword' respectively. For
Identity providers
, chooseEmail signup
; forApplication claims
, chooseEmail Addresses
,User's Object ID
and any other claims you want; forSign-up attributes
, chooseEmail Address
and anything else you like. -
Now we have a B2C web application and policies registered. Note that Azure AD adds a 'B2C_1_' prefix automatically to all policy names, so the policy names we will use are actually 'B2C_1_signin', 'B2C_1_signup', 'B2C_1_updateprofile' and 'B2C_1_resetpassword'.
To successfully use this sample, you need a working installation of Node.js.
Next, clone the sample repo and install the NPM.
From your shell or command line:
$ git clone git@github.com:AzureADQuickStarts/B2C-WebApp-OpenIDConnect-NodeJS.git
$ npm install
-
Provide the parameters in
exports.creds
in config.js as instructed. -
Update
exports.destroySessionUrl
in config.js, using your tenant name and signin policy name. If you want to redirect the users to a different url after they log out, update thepost_logout_redirect_uri
part as well. -
Set
exports.useMongoDBSessionStore
in config.js to false, if you want to use the default session store forexpress-session
. Note that the default session store is not suitable for production, you must use mongoDB or other compatible session stores. -
Update
exports.databaseUri
, if you want to use mongoDB session store and a different database uri. -
Update
exports.mongoDBSessionMaxAge
. Here you can specify how long you want to keep a session in mongoDB. The unit is second(s).
- Start mongoDB service.
If you are using mongoDB session store in this app, you have to install mongoDB and start the service first. If you are using the default session store, you can skip this step.
- Run the app.
Use the following command in terminal.
$ node app.js
Is the server output hard to understand?: We use bunyan
for logging in this sample. The console won't make much sense to you unless you also install bunyan and run the server like above but pipe it through the bunyan binary:
$ npm install -g bunyan
$ node app.js | bunyan
You will have a server successfully running on http://localhost:3000
.
We would like to acknowledge the folks who own/contribute to the following projects for their support of Azure Active Directory and their libraries that were used to build this sample. In places where we forked these libraries to add additional functionality, we ensured that the chain of forking remains intact so you can navigate back to the original package. Working with such great partners in the open source community clearly illustrates what open collaboration can accomplish. Thank you!
Code hosted on GitHub under MIT license