Cache federated identity MSAL clients#613
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR improves the federated identity credential (FIC) token acquisition path by caching the MSAL ConfidentialClientApplication instance per tenant, enabling MSAL’s internal token cache and reducing unnecessary token exchanges.
Changes:
- Cache
ConfidentialClientApplicationinstances used for FIC flows bytenantId. - Switch FIC client assertion from an eagerly-fetched managed identity token to an MSAL
clientAssertioncallback (lazy acquisition). - Extend unit tests to validate the callback-based assertion and per-tenant MSAL client caching behavior.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| packages/apps/src/token-manager.ts | Adds a per-tenant cache for federated identity MSAL clients and moves exchange-token acquisition into a lazy clientAssertion callback. |
| packages/apps/src/token-manager.spec.ts | Updates/extends tests to assert clientAssertion is a function, can be invoked to return the MI token, and that FIC clients are reused per tenant. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
corinagum
approved these changes
Jun 10, 2026
corinagum
added a commit
that referenced
this pull request
Jun 15, 2026
## Release 2.0.13 Merges main into release for stable publish. ### Notable changes since 2.0.12 - fix(client): use explicit Graph scopes for Teams Desktop NAA compatibility (#616) - ci: switch publish pipeline to 1ES Official template for CodeQL/SDL (#607) - ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608) - Refresh teams.apps README (#604) - Reject unauthenticated when no credentials (#506) - fix(api): conditionally set citation encodingFormat based on text presence (#579) - Improvements to the Teams MCP server example (#597) - Bump MSAL Node to v5 (#603) - Merge root message entities in Activity (#590) - TeamsSDK: Correct imports and return types in misc. packages (#589) - Cache federated identity MSAL clients (#613) ### Release steps 1. Merge this PR 2. Trigger the [release pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary) for `release` branch with **Public** publish type 3. Bump version on main to `2.0.14-preview.{height}` 4. Create git tag and GitHub Release page
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cache the MSAL confidential client used by federated identity credentials.
Why:
Recreating it on every token request means MSAL never gets to use its internal token cache. Reusing it avoids extra token exchanges and makes the FIC path less chatty.
Interesting bits:
The managed identity token is now provided through MSAL's lazy clientAssertion callback, so we only fetch the exchange token when MSAL actually needs it.
Reviewer tips:
Start in packages/apps/src/token-manager.ts. The important bit is the FIC client cache and callback assertion.
Testing: