Skip to content

fix(client): use explicit Graph scopes for Teams Desktop NAA compatibility#616

Merged
corinagum merged 2 commits into
mainfrom
cg/naa-desktop-repro
Jun 15, 2026
Merged

fix(client): use explicit Graph scopes for Teams Desktop NAA compatibility#616
corinagum merged 2 commits into
mainfrom
cg/naa-desktop-repro

Conversation

@corinagum

Copy link
Copy Markdown
Collaborator

Summary

Fixes #612 — Token acquisition fails on Teams Desktop but works on Teams Web.

Problem

On Teams Desktop, the OneAuth/WAM broker (via Nested App Auth) cannot resolve the .default scope for Graph token requests the way browser MSAL does. The graph client in @microsoft/teams.client hardcoded { scopes: ['.default'] }, which caused ApiContractViolation errors ("declined scopes") on Desktop.

Additionally, the MSAL config had authority: '' (overriding MSAL's sensible default) and did not set supportsNestedAppAuth: true.

Fix

  • graph-utils.ts: Accept explicit scopes via a getGraphScopes() parameter instead of hardcoding .default. Logs a warning when falling back to .default to aid discoverability.
  • app.ts: Pass the developer's prewarmScopes through to the graph client so Graph calls use explicit scopes.
  • msal-utils.ts: Remove empty authority override (let MSAL use its default common), add supportsNestedAppAuth: true, and handle ApiContractViolation errors from the Desktop broker as interaction-required (triggers popup fallback).

Testing

  • Reproduced the original failure on Teams Desktop (Mac) with the tab example
  • Confirmed the fix resolves the issue — Graph calls (/me) succeed on Desktop
  • All 41 unit tests pass with 100% coverage on msal-utils.ts and graph-utils.ts
  • Lint clean

Notes for reviewers

  • The .default scope still works on Web, so this is backward compatible. If prewarmScopes is not set, the graph client falls back to .default with a warning.
  • Developers targeting Desktop must set explicit scopes in msalOptions.prewarmScopes.

Copilot AI review requested due to automatic review settings June 15, 2026 17:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the @microsoft/teams.client authentication and Graph integration to improve Teams Desktop (Nested App Auth / OneAuth broker) compatibility by avoiding reliance on the Graph '.default' scope and by adjusting MSAL configuration/behavior for broker-specific errors.

Changes:

  • Update MSAL config defaults to enable Nested App Auth support and avoid overriding MSAL’s default authority.
  • Allow Graph requests to use explicit, developer-supplied scopes (with a warning when falling back to '.default').
  • Treat Desktop broker ApiContractViolation failures from acquireTokenSilent as interaction-required and fall back to acquireTokenPopup, with added unit tests.

Reviewed changes

Copilot reviewed 6 out of 6 changed files in this pull request and generated 3 comments.

Show a summary per file
File Description
packages/client/src/msal-utils.ts Adds broker-aware silent-token error handling and updates default MSAL configuration for NAA.
packages/client/src/msal-utils.spec.ts Adds/updates unit tests for the new MSAL config and broker error fallback behavior.
packages/client/src/graph-utils.ts Allows explicit Graph scopes to be supplied instead of hardcoding '.default', and warns on fallback.
packages/client/src/graph-utils.spec.ts Extends tests to validate explicit scopes and the '.default' warning behavior.
packages/client/src/app.ts Wires msalOptions.prewarmScopes through to Graph client scope selection and documents Desktop requirements.
packages/client/src/app.spec.ts Updates expectations for MSAL config and Graph client wiring in App initialization tests.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread packages/client/src/app.spec.ts
Comment thread packages/client/src/graph-utils.ts Outdated
Comment thread packages/client/src/app.ts Outdated
@corinagum
corinagum force-pushed the cg/naa-desktop-repro branch from fae4299 to 3fc0c9b Compare June 15, 2026 17:30
Comment thread packages/client/src/app.ts Outdated
@corinagum
corinagum added this pull request to the merge queue Jun 15, 2026
Merged via the queue into main with commit 2f76d34 Jun 15, 2026
6 checks passed
@corinagum
corinagum deleted the cg/naa-desktop-repro branch June 15, 2026 20:18
corinagum added a commit that referenced this pull request Jun 15, 2026
## Release 2.0.13

Merges main into release for stable publish.

### Notable changes since 2.0.12
- fix(client): use explicit Graph scopes for Teams Desktop NAA
compatibility (#616)
- ci: switch publish pipeline to 1ES Official template for CodeQL/SDL
(#607)
- ci: add weekly SDL pipeline for CodeQL/CredScan compliance (#608)
- Refresh teams.apps README (#604)
- Reject unauthenticated when no credentials (#506)
- fix(api): conditionally set citation encodingFormat based on text
presence (#579)
- Improvements to the Teams MCP server example (#597)
- Bump MSAL Node to v5 (#603)
- Merge root message entities in Activity (#590)
- TeamsSDK: Correct imports and return types in misc. packages (#589)
- Cache federated identity MSAL clients (#613)

### Release steps
1. Merge this PR
2. Trigger the [release
pipeline](https://dev.azure.com/DomoreexpGithub/Github_Pipelines/_build?definitionId=52&_a=summary)
for `release` branch with **Public** publish type
3. Bump version on main to `2.0.14-preview.{height}`
4. Create git tag and GitHub Release page
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Acquiring Token Fails in Teams Desktop but Works in Teams Web

4 participants