Feat: add signin/failure invoke handling#290
Merged
Merged
Conversation
corinagum
force-pushed
the
cg/signin-failure
branch
from
February 24, 2026 01:11
2a2c854 to
e240763
Compare
corinagum
force-pushed
the
cg/signin-failure
branch
from
February 25, 2026 17:26
e240763 to
1164803
Compare
corinagum
marked this pull request as ready for review
February 25, 2026 17:26
Contributor
There was a problem hiding this comment.
Pull request overview
Adds first-class routing/handling for Teams signin/failure invoke activities in the Python Apps SDK so SSO token-exchange failures are no longer silently swallowed, and developers can attach custom handlers.
Changes:
- Add a new
signin.failureroute configuration andApp.on_signin_failure()registration method. - Introduce a default
OauthHandlers.sign_in_failurehandler that logs and emits an"error"event. - Add unit + routing/middleware-chain integration tests for
signin/failure.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| packages/apps/src/microsoft_teams/apps/app.py | Registers the default signin/failure handler during app initialization. |
| packages/apps/src/microsoft_teams/apps/app_oauth.py | Implements default signin/failure handling (logging + error event emission). |
| packages/apps/src/microsoft_teams/apps/routing/activity_route_configs.py | Adds signin.failure to ACTIVITY_ROUTES with an invoke selector for name == "signin/failure". |
| packages/apps/src/microsoft_teams/apps/routing/generated_handlers.py | Adds on_signin_failure() decorator/overloads to register handlers for the new route. |
| packages/apps/tests/test_app_oauth.py | Adds tests covering default handler behavior and routing/middleware-chain execution for signin/failure. |
corinagum
force-pushed
the
cg/signin-failure
branch
from
March 3, 2026 17:26
e6eedf1 to
4551f98
Compare
lilyydu
reviewed
Mar 3, 2026
lilyydu
reviewed
Mar 3, 2026
heyitsaamir
approved these changes
Mar 4, 2026
heyitsaamir
left a comment
Collaborator
There was a problem hiding this comment.
lgtm. Acking that you verified.
corinagum
force-pushed
the
cg/signin-failure
branch
from
March 4, 2026 19:49
e92b8ab to
efdb8ab
Compare
lilyydu
approved these changes
Mar 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #285
Route and handle
signin/failureinvoke activities that Teams sends when SSO token exchange fails. Adds a system default handler that logs actionable warnings and emits error events, plus a signin.failure route for developer overrides.Previously, when Teams sent a
signin/failureinvoke (e.g., due to an SSO misconfiguration), the SDKs silently swallowed the failure with no logging, no error events, and no developer notification. This made SSO configuration issues extremely difficult to diagnose.User: hi
(No response from app)
The Problem
When a Teams app uses SSO (Single Sign-On) with a Token Exchange URL configured in the OAuth connection settings, Teams attempts a silent token exchange. If this fails -- for example, because the Entra app registration's "Expose an API" configuration doesn't match the Token Exchange URL -- Teams sends a
signin/failureinvoke activity with details like:{ "type": "invoke", "name": "signin/failure", "value": { "code": "resourcematchfailed", "message": "Resource match failed" } }Before this change, none of the three SDKs routed or handled this invoke. The failure was invisible to the user, SDK, and the developer. The user saw no sign-in card, no error message, and no indication of what went wrong.
Now, sign in failures with send a warning, emits error event, and return HTTP 200 by default. Developers can also register custom handlers if desired, for example:
Python:
Example log on
signin/failure:Note that the default behavior will still appear to fail silently for the user. There will be logs, but it will be up to the developer to determine how the user experiences the sign-in failure.
'resourcematchfailed'is an example of a setup error, however, and should not be an error that a 'real' user experiences. If desired, we could potentially modify the default behavior to send something to the user, but I'm disinclined to make that decision on the behalf of the developer.Feature work tested and verified in C#, PY, and TS.