mirror of
https://github.com/Micke-K/IntuneManagement.git
synced 2026-09-28 10:55:38 +02:00
Added support for System Broswer login
This commit is contained in:
@@ -10,7 +10,7 @@ This module manages Authentication for the application with MSAL. It is also res
|
|||||||
#>
|
#>
|
||||||
function Get-ModuleVersion
|
function Get-ModuleVersion
|
||||||
{
|
{
|
||||||
'3.9.8a'
|
'3.9.9'
|
||||||
}
|
}
|
||||||
|
|
||||||
$global:msalAuthenticator = $null
|
$global:msalAuthenticator = $null
|
||||||
@@ -137,12 +137,28 @@ function Invoke-InitializeModule
|
|||||||
Description = "Use WAM for enhanced login methods"
|
Description = "Use WAM for enhanced login methods"
|
||||||
}) "MSAL"
|
}) "MSAL"
|
||||||
|
|
||||||
|
Add-SettingsObject (New-Object PSObject -Property @{
|
||||||
|
Title = "Use System Browser for login"
|
||||||
|
Key = "UseSystemBrowser"
|
||||||
|
Type = "Boolean"
|
||||||
|
DefaultValue = $false
|
||||||
|
Description = "Use the default system browser (Edge/Chrome/Firefox) for interactive login instead of the embedded WebView. Required for passkey / FIDO2 sign-in. Redirect URI is forced to http://localhost when enabled. Takes precedence over WAM. Note: Requires restart"
|
||||||
|
}) "MSAL"
|
||||||
|
|
||||||
$script:MSALUseWAM = Get-SettingValue "UseWAM"
|
$script:MSALUseWAM = Get-SettingValue "UseWAM"
|
||||||
if($script:MSALUseWAM -and $PSVersionTable.PSVersion.Major -lt 7) {
|
if($script:MSALUseWAM -and $PSVersionTable.PSVersion.Major -lt 7) {
|
||||||
Write-Log "WAM is only supported in PowerShell 7 and later. Disabling WAM" 2
|
Write-Log "WAM is only supported in PowerShell 7 and later. Disabling WAM" 2
|
||||||
$script:MSALUseWAM = $false
|
$script:MSALUseWAM = $false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# System Browser takes precedence over WAM: passkey/FIDO2 login works in the real browser
|
||||||
|
# but not in the WAM pane or the embedded WebView. If both are enabled, disable WAM.
|
||||||
|
$script:MSALUseSystemBrowser = Get-SettingValue "UseSystemBrowser"
|
||||||
|
if($script:MSALUseSystemBrowser -and $script:MSALUseWAM) {
|
||||||
|
Write-Log "Both UseWAM and UseSystemBrowser are enabled - the system browser takes precedence for interactive login" 2
|
||||||
|
$script:MSALUseWAM = $false
|
||||||
|
}
|
||||||
|
|
||||||
Add-MSALPrereq
|
Add-MSALPrereq
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -931,7 +947,19 @@ function Get-MSALApp
|
|||||||
|
|
||||||
[void]$appBuilder.WithAuthority($authority)
|
[void]$appBuilder.WithAuthority($authority)
|
||||||
|
|
||||||
if($appInfo.RedirectUri) { [void]$appBuilder.WithRedirectUri($appInfo.RedirectUri) }
|
# System Browser mode: MSAL's system-browser flow only accepts loopback redirects,
|
||||||
|
# so any custom redirect URI (nativeclient, ms-appx-web://, etc.) is replaced with
|
||||||
|
# http://localhost. The app registration in Entra must have this loopback URI added
|
||||||
|
# under the "Mobile and desktop applications" platform for the login to succeed.
|
||||||
|
$redirectUri = $appInfo.RedirectUri
|
||||||
|
if($script:MSALUseSystemBrowser -and $redirectUri -and ($redirectUri -notmatch '^http://localhost')) {
|
||||||
|
Write-LogDebug "UseSystemBrowser: overriding redirect URI '$redirectUri' with http://localhost"
|
||||||
|
$redirectUri = "http://localhost"
|
||||||
|
}
|
||||||
|
elseif($script:MSALUseSystemBrowser -and -not $redirectUri) {
|
||||||
|
$redirectUri = "http://localhost"
|
||||||
|
}
|
||||||
|
if($redirectUri) { [void]$appBuilder.WithRedirectUri($redirectUri) }
|
||||||
|
|
||||||
[void] $appBuilder.WithClientName("CloudAPIPowerShellManagement")
|
[void] $appBuilder.WithClientName("CloudAPIPowerShellManagement")
|
||||||
[void] $appBuilder.WithClientVersion($PSVersionTable.PSVersion)
|
[void] $appBuilder.WithClientVersion($PSVersionTable.PSVersion)
|
||||||
@@ -1291,6 +1319,15 @@ function Connect-MSALUser
|
|||||||
[void]$aquireTokenObj.WithParentActivityOrWindow($ParentWindow)
|
[void]$aquireTokenObj.WithParentActivityOrWindow($ParentWindow)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# UseSystemBrowser: force MSAL to launch the default system browser instead of
|
||||||
|
# any embedded WebView. Required for passkey / FIDO2 sign-in which the embedded
|
||||||
|
# WebView cannot service.
|
||||||
|
if($script:MSALUseSystemBrowser)
|
||||||
|
{
|
||||||
|
try { [void]$aquireTokenObj.WithUseEmbeddedWebView($false) }
|
||||||
|
catch { Write-LogDebug "WithUseEmbeddedWebView unavailable: $($_.Exception.Message)" }
|
||||||
|
}
|
||||||
|
|
||||||
# If we need a consent (e.g. App is not approved in the environment)
|
# If we need a consent (e.g. App is not approved in the environment)
|
||||||
if ($script:authenticationFailure.Classification -eq "ConsentRequired")
|
if ($script:authenticationFailure.Classification -eq "ConsentRequired")
|
||||||
{
|
{
|
||||||
@@ -1346,7 +1383,17 @@ function Connect-MSALUser
|
|||||||
$appBuilder = [Microsoft.Identity.Client.PublicClientApplicationBuilder]::Create($global:appObj.ClientID)
|
$appBuilder = [Microsoft.Identity.Client.PublicClientApplicationBuilder]::Create($global:appObj.ClientID)
|
||||||
if($tenantId) { [void]$appBuilder.WithAuthority("https://$((Get-MSALAppAuthority))/$($tenantId)") }
|
if($tenantId) { [void]$appBuilder.WithAuthority("https://$((Get-MSALAppAuthority))/$($tenantId)") }
|
||||||
else { [void]$appBuilder.WithAuthority($global:MSALApp.Authority) }
|
else { [void]$appBuilder.WithAuthority($global:MSALApp.Authority) }
|
||||||
if($global:appObj.RedirectUri) { [void]$appBuilder.WithRedirectUri($global:appObj.RedirectUri) }
|
|
||||||
|
# Match the redirect URI substitution done in Get-MSALApp - keeps this
|
||||||
|
# secondary MSAL app consistent with System Browser mode.
|
||||||
|
$tenantRedirectUri = $global:appObj.RedirectUri
|
||||||
|
if($script:MSALUseSystemBrowser -and $tenantRedirectUri -and ($tenantRedirectUri -notmatch '^http://localhost')) {
|
||||||
|
$tenantRedirectUri = "http://localhost"
|
||||||
|
}
|
||||||
|
elseif($script:MSALUseSystemBrowser -and -not $tenantRedirectUri) {
|
||||||
|
$tenantRedirectUri = "http://localhost"
|
||||||
|
}
|
||||||
|
if($tenantRedirectUri) { [void]$appBuilder.WithRedirectUri($tenantRedirectUri) }
|
||||||
|
|
||||||
Add-MSALProxy $appBuilder
|
Add-MSALProxy $appBuilder
|
||||||
|
|
||||||
@@ -1367,6 +1414,11 @@ function Connect-MSALUser
|
|||||||
#[void]$AquireTokenObj.WithAccount($authResult.Account)
|
#[void]$AquireTokenObj.WithAccount($authResult.Account)
|
||||||
[void]$AquireTokenObj.WithLoginHint($authResult.Account.Username)
|
[void]$AquireTokenObj.WithLoginHint($authResult.Account.Username)
|
||||||
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::NoPrompt)
|
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::NoPrompt)
|
||||||
|
if($script:MSALUseSystemBrowser)
|
||||||
|
{
|
||||||
|
try { [void]$AquireTokenObj.WithUseEmbeddedWebView($false) }
|
||||||
|
catch { Write-LogDebug "WithUseEmbeddedWebView unavailable: $($_.Exception.Message)" }
|
||||||
|
}
|
||||||
$tmpResults = Get-MsalAuthenticationToken $AquireTokenObj
|
$tmpResults = Get-MsalAuthenticationToken $AquireTokenObj
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user