Skip to content

Live Application Evidence

copilot edited this page Jun 30, 2026 · 3 revisions

Live application evidence

This page captures the deployed Croesus On-Behalf-Of (OBO) demo running in Azure App Service. The screenshots and request traces below were taken against the live endpoints, not a local build.

Deployed endpoints

Component URL Runtime
SPA (public client) https://croesus-spa.azurewebsites.net Linux App Service, Node 20, static Vite bundle served with pm2 serve --spa
API (confidential client) https://croesus-api.azurewebsites.net Linux App Service, .NET 8

SPA landing page

The single-page app loads and explains the difference between token replay and a real OBO exchange. It requests only the API scope and never a Microsoft Graph scope.

Croesus SPA landing page showing the On-Behalf-Of flow demo and a Sign in button:

Microsoft Entra sign-in

Selecting Sign in drives a Microsoft Entra authorization request for the SPA client ID (06ef7c0a-...) and the API scope (api://bc6338a5-.../access_as_user). Entra renders the sign-in prompt with no application or consent errors, which confirms the app registration, redirect URI, and exposed scope are wired correctly.

Microsoft Entra sign-in page rendered for the Croesus SPA client and API scope:

API enforces bearer authentication

The middle-tier API rejects an unauthenticated call to the protected endpoint, returning 401 Unauthorized with a WWW-Authenticate: Bearer challenge. This proves the API is live and enforcing token validation before any OBO exchange occurs.

GET https://croesus-api.azurewebsites.net/api/me

HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer

Why the full OBO claim evidence is validated interactively

The demo tenant enforces multi-factor authentication for every user through a Microsoft-managed Conditional Access policy. Completing the OBO exchange therefore requires an interactive sign-in that satisfies MFA in the browser. A headless resource-owner-password (ROPC) grant cannot satisfy MFA and fails with AADSTS50079, so the automated smoke and negative tests are gated off by default (see Pipeline execution evidence). To capture the decoded two-leg claim evidence, sign in interactively at the SPA and follow docs/obo-demo-guide.md.

Clone this wiki locally