mirror of
https://github.com/Micke-K/IntuneManagement.git
synced 2026-09-28 10:55:38 +02:00
Added support for System Broswer login
This commit is contained in:
@@ -10,7 +10,7 @@ This module manages Authentication for the application with MSAL. It is also res
|
||||
#>
|
||||
function Get-ModuleVersion
|
||||
{
|
||||
'3.9.8a'
|
||||
'3.9.9'
|
||||
}
|
||||
|
||||
$global:msalAuthenticator = $null
|
||||
@@ -137,12 +137,28 @@ function Invoke-InitializeModule
|
||||
Description = "Use WAM for enhanced login methods"
|
||||
}) "MSAL"
|
||||
|
||||
Add-SettingsObject (New-Object PSObject -Property @{
|
||||
Title = "Use System Browser for login"
|
||||
Key = "UseSystemBrowser"
|
||||
Type = "Boolean"
|
||||
DefaultValue = $false
|
||||
Description = "Use the default system browser (Edge/Chrome/Firefox) for interactive login instead of the embedded WebView. Required for passkey / FIDO2 sign-in. Redirect URI is forced to http://localhost when enabled. Takes precedence over WAM. Note: Requires restart"
|
||||
}) "MSAL"
|
||||
|
||||
$script:MSALUseWAM = Get-SettingValue "UseWAM"
|
||||
if($script:MSALUseWAM -and $PSVersionTable.PSVersion.Major -lt 7) {
|
||||
Write-Log "WAM is only supported in PowerShell 7 and later. Disabling WAM" 2
|
||||
$script:MSALUseWAM = $false
|
||||
}
|
||||
|
||||
# System Browser takes precedence over WAM: passkey/FIDO2 login works in the real browser
|
||||
# but not in the WAM pane or the embedded WebView. If both are enabled, disable WAM.
|
||||
$script:MSALUseSystemBrowser = Get-SettingValue "UseSystemBrowser"
|
||||
if($script:MSALUseSystemBrowser -and $script:MSALUseWAM) {
|
||||
Write-Log "Both UseWAM and UseSystemBrowser are enabled - the system browser takes precedence for interactive login" 2
|
||||
$script:MSALUseWAM = $false
|
||||
}
|
||||
|
||||
Add-MSALPrereq
|
||||
}
|
||||
|
||||
@@ -931,7 +947,19 @@ function Get-MSALApp
|
||||
|
||||
[void]$appBuilder.WithAuthority($authority)
|
||||
|
||||
if($appInfo.RedirectUri) { [void]$appBuilder.WithRedirectUri($appInfo.RedirectUri) }
|
||||
# System Browser mode: MSAL's system-browser flow only accepts loopback redirects,
|
||||
# so any custom redirect URI (nativeclient, ms-appx-web://, etc.) is replaced with
|
||||
# http://localhost. The app registration in Entra must have this loopback URI added
|
||||
# under the "Mobile and desktop applications" platform for the login to succeed.
|
||||
$redirectUri = $appInfo.RedirectUri
|
||||
if($script:MSALUseSystemBrowser -and $redirectUri -and ($redirectUri -notmatch '^http://localhost')) {
|
||||
Write-LogDebug "UseSystemBrowser: overriding redirect URI '$redirectUri' with http://localhost"
|
||||
$redirectUri = "http://localhost"
|
||||
}
|
||||
elseif($script:MSALUseSystemBrowser -and -not $redirectUri) {
|
||||
$redirectUri = "http://localhost"
|
||||
}
|
||||
if($redirectUri) { [void]$appBuilder.WithRedirectUri($redirectUri) }
|
||||
|
||||
[void] $appBuilder.WithClientName("CloudAPIPowerShellManagement")
|
||||
[void] $appBuilder.WithClientVersion($PSVersionTable.PSVersion)
|
||||
@@ -1291,6 +1319,15 @@ function Connect-MSALUser
|
||||
[void]$aquireTokenObj.WithParentActivityOrWindow($ParentWindow)
|
||||
}
|
||||
|
||||
# UseSystemBrowser: force MSAL to launch the default system browser instead of
|
||||
# any embedded WebView. Required for passkey / FIDO2 sign-in which the embedded
|
||||
# WebView cannot service.
|
||||
if($script:MSALUseSystemBrowser)
|
||||
{
|
||||
try { [void]$aquireTokenObj.WithUseEmbeddedWebView($false) }
|
||||
catch { Write-LogDebug "WithUseEmbeddedWebView unavailable: $($_.Exception.Message)" }
|
||||
}
|
||||
|
||||
# If we need a consent (e.g. App is not approved in the environment)
|
||||
if ($script:authenticationFailure.Classification -eq "ConsentRequired")
|
||||
{
|
||||
@@ -1346,7 +1383,17 @@ function Connect-MSALUser
|
||||
$appBuilder = [Microsoft.Identity.Client.PublicClientApplicationBuilder]::Create($global:appObj.ClientID)
|
||||
if($tenantId) { [void]$appBuilder.WithAuthority("https://$((Get-MSALAppAuthority))/$($tenantId)") }
|
||||
else { [void]$appBuilder.WithAuthority($global:MSALApp.Authority) }
|
||||
if($global:appObj.RedirectUri) { [void]$appBuilder.WithRedirectUri($global:appObj.RedirectUri) }
|
||||
|
||||
# Match the redirect URI substitution done in Get-MSALApp - keeps this
|
||||
# secondary MSAL app consistent with System Browser mode.
|
||||
$tenantRedirectUri = $global:appObj.RedirectUri
|
||||
if($script:MSALUseSystemBrowser -and $tenantRedirectUri -and ($tenantRedirectUri -notmatch '^http://localhost')) {
|
||||
$tenantRedirectUri = "http://localhost"
|
||||
}
|
||||
elseif($script:MSALUseSystemBrowser -and -not $tenantRedirectUri) {
|
||||
$tenantRedirectUri = "http://localhost"
|
||||
}
|
||||
if($tenantRedirectUri) { [void]$appBuilder.WithRedirectUri($tenantRedirectUri) }
|
||||
|
||||
Add-MSALProxy $appBuilder
|
||||
|
||||
@@ -1367,6 +1414,11 @@ function Connect-MSALUser
|
||||
#[void]$AquireTokenObj.WithAccount($authResult.Account)
|
||||
[void]$AquireTokenObj.WithLoginHint($authResult.Account.Username)
|
||||
[void]$AquireTokenObj.WithPrompt([Microsoft.Identity.Client.Prompt]::NoPrompt)
|
||||
if($script:MSALUseSystemBrowser)
|
||||
{
|
||||
try { [void]$AquireTokenObj.WithUseEmbeddedWebView($false) }
|
||||
catch { Write-LogDebug "WithUseEmbeddedWebView unavailable: $($_.Exception.Message)" }
|
||||
}
|
||||
$tmpResults = Get-MsalAuthenticationToken $AquireTokenObj
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user