Log Microsoft's error when the sign-in token exchange fails

The AADSTS code and description were discarded, leaving only a generic
"could not verify" message. Log them (not to the browser) so a bad secret,
SPA platform, or redirect mismatch can be diagnosed from container logs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
uhlwoogiandClaude Opus 5.5 committed 2026-10-02 23:48:17 +00:00
1 parent a51d5825ce
commit d1c9b7bebb
1 file changed
+5 -1
+5 -1
View File
@@ -258,7 +258,11 @@ async function finishMicrosoftLogin(url, response) {
}) })
}); });
const tokens = await tokenResponse.json(); const tokens = await tokenResponse.json();
if (!tokenResponse.ok || !tokens.id_token) throw new Error("Microsoft could not verify this sign-in."); if (!tokenResponse.ok || !tokens.id_token) {
// Microsoft's AADSTS code says why (bad secret, SPA platform, redirect mismatch); keep it in the logs only.
console.error("Microsoft token exchange failed:", tokenResponse.status, tokens.error || "", String(tokens.error_description || "").split(/\r?\n/)[0]);
throw new Error("Microsoft could not verify this sign-in.");
}
const claims = await validateMicrosoftIdToken(tokens.id_token, pending.nonce); const claims = await validateMicrosoftIdToken(tokens.id_token, pending.nonce);
const email = String(claims.email || claims.preferred_username || "").trim().toLowerCase(); const email = String(claims.email || claims.preferred_username || "").trim().toLowerCase();
if (!email || !ALLOWED_EMAILS.has(email)) { if (!email || !ALLOWED_EMAILS.has(email)) {