Azure-Samples / Azure-Samples/communication-services-javascript-quickstarts
ClientAuthError in manage-teams-identity-mobile-and-desktop
- Dominant language
- JavaScript
- Stars
- 108
- Forks
- 207
- PR merge metrics
- No merged PRs in 30d
Description
I want to call with an ACS resource related to my Microsoft Teams user (add-1-on-1-cte-video-calling). So to get the right ACS token, I wanted to get mine with the tool: manage-teams-identity-mobile-and-desktop
All environment variables are set, and it runs on the URL http://localhost:3000
http://localhost:3000/redirect is set on the Azure portal as a Single page application redirect URL for my Teams BOT.
So everything should be okay, but when I run this, after login my Teams User the callback URL called back, but not with the AccessToken, but this error
```
{"errorCode":"network_error","errorMessage":"Network request failed. Please check network trace to determine root cause. | Fetch client threw: Error: HTTP status code 400 | Attempted to reach: https://login.microsoftonline.com/[MY_TENANT_ID_HIDDEN]/oauth2/v2.0/token","subError":"","name":"ClientAuthError"}
```
Teams Bot has all the necessary permissions.
### This issue is for a: (mark with an `x`)
```
- [ x ] bug report -> please search issues before submitting
- [ ] feature request
- [ ] documentation issue or request
- [ ] regression (a behavior that used to work and stopped in a new release)
```
### Minimal steps to reproduce
- run manage-teams-identity-mobile-and-desktop
- login with my Teams user
- get back the error above
### Any log messages given by the failure
>
### Expected/desired behavior
- I would like to get back the ACS access token of the impersonated Teams User
### OS and Version?
- Windows 11
### Versions
- code was downloaded a couple days ago
Contributor guide
Research direction
Start with the manage-teams-identity-mobile-and-desktop entry point and reproduce the login flow on Windows 11 at http://localhost:3000. Inspect the network trace for the request to the Microsoft identity platform token endpoint and compare the configured SPA redirect URL with the request. Done means the callback completes without ClientAuthError and returns the expected ACS access token.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- authentication
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100