Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

MSAL authentication fails when using PCF Canvas App sample inside Power Apps iOS WKWebView

Aperta
#532 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
45/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
typescript

Direzione di ricerca

Inizia con ui/embed/pcf-canvas-app e traccia la sua inizializzazione di MSAL Browser e il flusso di acquisizione dei token. Riproduci l’esempio nella Power Apps iOS WKWebView, registrando l’errore di inizializzazione o di acquisizione silenziosa e le richieste a login.microsoftonline.com. Il lavoro è completato quando il comportamento supportato è documentato oppure il flusso di autenticazione funziona nell’ambiente indicato, con i test o i passaggi di riproduzione pertinenti aggiornati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Hi team,

I am testing the pcf-canvas-app sample from this repository:

https://github.com/microsoft/CopilotStudioSamples/tree/main/ui/embed/pcf-canvas-app

The sample works as expected in desktop browsers, but authentication fails when running inside Power Apps iOS mobile application, where the Canvas App is hosted through WKWebView.

The issue appears to be related to MSAL Browser initialization / authentication flow limitations in WKWebView.

Environment
Sample: ui/embed/pcf-canvas-app
Host application: Power Apps Canvas App
Platform: iOS Power Apps Mobile
Web runtime: WKWebView
Authentication: Microsoft Entra ID / M365 authentication
MSAL: Browser-based authentication flow
Expected behavior

When opening the Canvas App on iOS:

PCF control initializes successfully
MSAL Browser creates the authentication client
User is redirected to Microsoft login page
Token acquisition succeeds
Copilot Studio agent connection is established
Actual behavior

The authentication initialization fails inside iOS WKWebView.

The flow looks like:

Power Apps (iOS WKWebView)
|
v
PCF
|
v
MSAL Browser
|
v
login.microsoftonline.com

MSAL fails during initialization or token acquisition.

As a result, the PCF control cannot authenticate and the Copilot Studio agent cannot be loaded.

Possible root cause

It seems related to known limitations of using MSAL Browser inside WKWebView:

Redirect based login may not work correctly
Popup authentication is unavailable
Third-party cookie restrictions may block authentication state
Silent token acquisition may fail
Web storage behavior differs from desktop browsers

Power Apps iOS uses WKWebView instead of a full browser environment, which may cause MSAL Browser assumptions to fail.

Error details

Example behavior:

Unable to initialize MSAL authentication client

or

Failed to acquire token silently

Network requests to:

https://login.microsoftonline.com/

do not complete successfully.

Questions
Is pcf-canvas-app officially supported inside Power Apps Mobile (iOS)?
Is there a recommended authentication approach for PCF controls running inside Canvas Apps on iOS?
Should this sample use another authentication mechanism instead of MSAL Browser?

For example:

Native Power Apps authentication context
Entra ID token provided by host application
MSAL native authentication flow
Alternative PCF authentication pattern
Additional information

The current implementation works correctly in:

✅ Desktop browser
✅ Standard browser environments

The issue only reproduces in:

❌ Power Apps iOS Mobile App (WKWebView)

Possible improvement

Could the sample documentation include a note about mobile/WKWebView authentication limitations?

For example:

"This sample uses MSAL Browser authentication. Running inside embedded WebView containers such as Power Apps Mobile iOS may require additional authentication handling."

Thanks for reviewing this issue.

Lingua principale
TypeScript
Stelle
803
Fork
493
Merge medio
8g 20h
PR unite (30g)
1

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di microsoft/CopilotStudioSamples

Tutte le issue di microsoft/CopilotStudioSamples

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.