-
Notifications
You must be signed in to change notification settings - Fork 0
Home
Emmanuel Knafo edited this page Oct 1, 2026
·
6 revisions
Croesus is a mock SaaS demo of the Microsoft Entra On-Behalf-Of (OBO) flow. A public-client SPA acquires a token for a middle-tier API; the API exchanges that token for a distinct Microsoft Graph token by authenticating its own confidential-client credential. The SPA never holds a Graph token, and the two tokens carry different audiences — the behavioral signature of a real OBO rather than token replay.
- BFF demo walkthrough — the full deploy-and-prove flow with screenshots: Azure resources, both Entra app registrations, App Service settings, sign-in, BFF and API evidence, Application Insights, Log Analytics, and alerts.
- Reference reading: Backends for Frontends pattern and Secure a Blazor Web App with OIDC (YARP and Aspire).
- Live application evidence — screenshots of the deployed SPA, the Entra sign-in, and the API enforcing bearer authentication.
- Pipeline execution evidence — the latest green CI run, job and step results, and how the MFA constraint is handled.
- Token Protection 1008 evidence — captured sign-in logs showing the bound (0) versus unbound (1008) Token Protection signature reproduced on the Croesus app, with the KQL to reproduce.
- Live demo state — durable record of the live demo objects (replay gate, Conditional Access policy, SPA to Graph grant) with identifiers, screenshots, and reversible teardown commands.
-
API reference — live Swagger UI, the OpenAPI document, the
/api/me(OBO good path) and gated/api/replayoperations, and the wrong-versus-right framing.
- Repository: https://github.com/devopsabcs-engineering/croesus
- Demo guide: docs/obo-demo-guide.md