Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

MSAL issue with Copilot Studio SDK

Aperta
#527 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
55/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
react, typescript

Direzione di ricerca

Inizia individuando l'inizializzazione di MSAL e le chiamate a loginPopup nel webpart, quindi esamina in che modo il rendering di React influisce sull'istanza MSAL. Verifica che venga riutilizzata una sola istanza e che venga chiamato handleRedirectPromise(). Il lavoro è completato quando l'autenticazione restituisce il token al webpart e il popup SharePoint reindirizzato si chiude automaticamente.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Issue Description:
We developed a webpart to access copilot agent data. When configuring the webpart on a SharePoint site, it opens a popup for authentication. After authentication succeeds, the token is not being returned to the webpart.

Microsoft Support team findings below,

The Auth pop-up opening the Sharepoint site is a direct symptom of new MSAL instance created on every call combined with missing handleRedirectPromise().
Here's what's happening step by step:

  1. loginPopup() opens a popup to login.microsoftonline.com.
  2. User picks their account → Azure AD authenticates successfully
  3. Azure AD redirects the popup to the redirect Uri, which is settings. redirectUri || window.location.origin — i.e., the SharePoint site URL
  4. The popup now loads the full SharePoint site instead of closing
    The popup should close automatically at this point. MSAL's popup flow works by having the parent window monitor the popup's URL via polling. When the popup redirects back to the same origin with the auth code in the URL hash, the parent MSAL instance reads the code, processes it, and closes the popup.
    But because a new MSAL instance is created on every call and handleRedirectPromise() is never called:
    • The MSAL instance that opened the popup may have been garbage collected (React re-render)
    • The polling interval that monitors the popup URL is gone
    • Nobody reads the auth code from the popup's URL
    • Nobody closes the popup
    • The popup just sits there showing the SharePoint site it was redirected to
    So the SharePoint site loading in the popup is the redirect working correctly from Azure AD's side — but MSAL on the parent side failing to intercept and close it.

To fix this, the MSAL instance must be a singleton, and handleRedirectPromise() must be called.

Lingua principale
TypeScript
Stelle
803
Fork
493
Merge medio
8g 20h
PR unite (30g)
1

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/CopilotStudioSamples

Tutte le issue di microsoft/CopilotStudioSamples

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.