-
Notifications
You must be signed in to change notification settings - Fork 0
Live Application Evidence
This page captures the deployed Croesus On-Behalf-Of (OBO) demo running in Azure App Service. The screenshots and request traces below were taken against the live endpoints, not a local build.
| Component | URL | Runtime |
|---|---|---|
| SPA (public client) | https://croesus-spa.azurewebsites.net | Linux App Service, Node 20, static Vite bundle served with pm2 serve --spa
|
| API (confidential client) | https://croesus-api.azurewebsites.net | Linux App Service, .NET 8 |
The single-page app loads and explains the difference between token replay and a real OBO exchange. It requests only the API scope and never a Microsoft Graph scope.
Croesus SPA landing page showing the On-Behalf-Of flow demo and a Sign in button:

Selecting Sign in drives a Microsoft Entra authorization request for the SPA client ID (06ef7c0a-...) and the API scope (api://bc6338a5-.../access_as_user). Entra renders the sign-in prompt with no application or consent errors, which confirms the app registration, redirect URI, and exposed scope are wired correctly.
Microsoft Entra sign-in page rendered for the Croesus SPA client and API scope:

The middle-tier API rejects an unauthenticated call to the protected endpoint, returning 401 Unauthorized with a WWW-Authenticate: Bearer challenge. This proves the API is live and enforcing token validation before any OBO exchange occurs.
GET https://croesus-api.azurewebsites.net/api/me
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer
The demo tenant enforces multi-factor authentication for every user through a Microsoft-managed Conditional Access policy. Completing the OBO exchange therefore requires an interactive sign-in that satisfies MFA in the browser. A headless resource-owner-password (ROPC) grant cannot satisfy MFA and fails with AADSTS50079, so the automated smoke and negative tests are gated off by default (see Pipeline execution evidence). To capture the decoded two-leg claim evidence, sign in interactively at the SPA and follow docs/obo-demo-guide.md.