The current environment is Blazor Wasm, and the API tool used is Refit, and the current requirement is to bring the AD information in the Windows domain when logging in to request the API in exchange for a token #1690
|
But when I set httpclient's UseDefaultCredentials runtime, it will get an error, of course I know the reason, because this is a server-side function, so I want to ask how to do this scenario |
Answered by
glennawatson
Jun 16, 2026
Replies: 1 comment
|
This is a platform limitation, not a Refit one. In Blazor WebAssembly all HTTP requests go through the browser fetch API, so HttpClientHandler.UseDefaultCredentials and Windows/AD integrated auth are not available - the browser sandbox does not expose the Windows domain identity to WASM. That is why you get the runtime error. Options for the WASM scenario:
services
.AddRefitClient<IMyApi>()
.ConfigureHttpClient(c => c.BaseAddress = new Uri(BaseUrl))
.AddHttpMessageHandler(() => new AuthHeaderHandler(tokenProvider));
Short version: capture the AD identity server-side and exchange it for a token; Refit then just carries the token. There is nothing Refit can set to make WASM use Windows credentials directly. |
0 replies
Answer selected by
glennawatson
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
This is a platform limitation, not a Refit one. In Blazor WebAssembly all HTTP requests go through the browser fetch API, so HttpClientHandler.UseDefaultCredentials and Windows/AD integrated auth are not available - the browser sandbox does not expose the Windows domain identity to WASM. That is why you get the runtime error.
Options for the WASM scenario: