Azure-Samples / Azure-Samples/communication-services-javascript-quickstarts

ClientAuthError in manage-teams-identity-mobile-and-desktop

Open
#229 0 comments 0 reactions 0 assignees View on GitHub
status:triage
Dominant language
JavaScript
Stars
108
Forks
207
PR merge metrics
No merged PRs in 30d

Description

I want to call with an ACS resource related to my Microsoft Teams user (add-1-on-1-cte-video-calling). So to get the right ACS token, I wanted to get mine with the tool: manage-teams-identity-mobile-and-desktop

All environment variables are set, and it runs on the URL http://localhost:3000
http://localhost:3000/redirect is set on the Azure portal as a Single page application redirect URL for my Teams BOT.
So everything should be okay, but when I run this, after login my Teams User the callback URL called back, but not with the AccessToken, but this error
```
{"errorCode":"network_error","errorMessage":"Network request failed. Please check network trace to determine root cause. | Fetch client threw: Error: HTTP status code 400 | Attempted to reach: https://login.microsoftonline.com/[MY_TENANT_ID_HIDDEN]/oauth2/v2.0/token","subError":"","name":"ClientAuthError"}
```
Teams Bot has all the necessary permissions.

### This issue is for a: (mark with an `x`)
```
- [ x ] bug report -> please search issues before submitting
- [ ] feature request
- [ ] documentation issue or request
- [ ] regression (a behavior that used to work and stopped in a new release)
```

### Minimal steps to reproduce
- run manage-teams-identity-mobile-and-desktop
- login with my Teams user
- get back the error above

### Any log messages given by the failure
>

### Expected/desired behavior
- I would like to get back the ACS access token of the impersonated Teams User

### OS and Version?
- Windows 11

### Versions
- code was downloaded a couple days ago

Contributor guide

Open the contributing guide

Research direction

Start with the manage-teams-identity-mobile-and-desktop entry point and reproduce the login flow on Windows 11 at http://localhost:3000. Inspect the network trace for the request to the Microsoft identity platform token endpoint and compare the configured SPA redirect URL with the request. Done means the callback completes without ClientAuthError and returns the expected ACS access token.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
authentication
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.