fix(msteams): remove .default suffix from graph scopes #1507
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The @microsoft/agents-hosting SDK's MsalTokenProvider automatically appends
/.defaultto all scope strings in its token acquisition methods (acquireAccessTokenViaSecret, acquireAccessTokenViaFIC, acquireAccessTokenViaWID, acquireTokenWithCertificate in msalTokenProvider.ts). This is consistent SDK behavior, not a recent change.The current code is including
.defaultin scope URLs, resulting in invalid double suffixes likehttps://graph.microsoft.com/.default/.default. I am not sure how the .default postfixed worked in the past for you if I am honest.This was confirmed to cause Graph API authentication errors. Removing the
.defaultsuffix from our scope strings allows the SDK to append it correctly, resolving the issue. I confirmed it manually on my teams setupBefore: we pass
.default-> SDK appends -> double.default(broken)After: we pass base URL -> SDK appends -> single
.default(works)