Skip to content

Cache federated identity MSAL clients#613

Merged
heyitsaamir merged 2 commits into
mainfrom
cache-fic-msal-clients
Jun 10, 2026
Merged

Cache federated identity MSAL clients#613
heyitsaamir merged 2 commits into
mainfrom
cache-fic-msal-clients

Conversation

@heyitsaamir

@heyitsaamir heyitsaamir commented Jun 10, 2026

Copy link
Copy Markdown
Collaborator

Cache the MSAL confidential client used by federated identity credentials.

Why:
Recreating it on every token request means MSAL never gets to use its internal token cache. Reusing it avoids extra token exchanges and makes the FIC path less chatty.

Interesting bits:
The managed identity token is now provided through MSAL's lazy clientAssertion callback, so we only fetch the exchange token when MSAL actually needs it.

Reviewer tips:
Start in packages/apps/src/token-manager.ts. The important bit is the FIC client cache and callback assertion.

Testing:

  • Manual VM test of the FIC token flow

Copilot AI review requested due to automatic review settings June 10, 2026 06:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR improves the federated identity credential (FIC) token acquisition path by caching the MSAL ConfidentialClientApplication instance per tenant, enabling MSAL’s internal token cache and reducing unnecessary token exchanges.

Changes:

  • Cache ConfidentialClientApplication instances used for FIC flows by tenantId.
  • Switch FIC client assertion from an eagerly-fetched managed identity token to an MSAL clientAssertion callback (lazy acquisition).
  • Extend unit tests to validate the callback-based assertion and per-tenant MSAL client caching behavior.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
packages/apps/src/token-manager.ts Adds a per-tenant cache for federated identity MSAL clients and moves exchange-token acquisition into a lazy clientAssertion callback.
packages/apps/src/token-manager.spec.ts Updates/extends tests to assert clientAssertion is a function, can be invoked to return the MI token, and that FIC clients are reused per tenant.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread packages/apps/src/token-manager.ts
@heyitsaamir
heyitsaamir added this pull request to the merge queue Jun 10, 2026
Merged via the queue into main with commit 8e207f9 Jun 10, 2026
6 checks passed
@heyitsaamir
heyitsaamir deleted the cache-fic-msal-clients branch June 10, 2026 19:19
corinagum added a commit that referenced this pull request Jun 15, 2026
## Release 2.0.13

Merges main into release for stable publish.

### Notable changes since 2.0.12
- fix(client): use explicit Graph scopes for Teams Desktop NAA
compatibility (#616)
- ci: switch publish pipeline to 1ES Official template for CodeQL/SDL
(#607)
- ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608)
- Refresh teams.apps README (#604)
- Reject unauthenticated when no credentials (#506)
- fix(api): conditionally set citation encodingFormat based on text
presence (#579)
- Improvements to the Teams MCP server example (#597)
- Bump MSAL Node to v5 (#603)
- Merge root message entities in Activity (#590)
- TeamsSDK: Correct imports and return types in misc. packages (#589)
- Cache federated identity MSAL clients (#613)

### Release steps
1. Merge this PR
2. Trigger the [release
pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary)
for `release` branch with **Public** publish type
3. Bump version on main to `2.0.14-preview.{height}`
4. Create git tag and GitHub Release page
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants