Log Microsoft's error when the sign-in token exchange fails
The AADSTS code and description were discarded, leaving only a generic "could not verify" message. Log them (not to the browser) so a bad secret, SPA platform, or redirect mismatch can be diagnosed from container logs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
a51d5825ce
commit
d1c9b7bebb
1 file changed
+5
-1
@@ -258,7 +258,11 @@ async function finishMicrosoftLogin(url, response) {
|
|||||||
})
|
})
|
||||||
});
|
});
|
||||||
const tokens = await tokenResponse.json();
|
const tokens = await tokenResponse.json();
|
||||||
if (!tokenResponse.ok || !tokens.id_token) throw new Error("Microsoft could not verify this sign-in.");
|
if (!tokenResponse.ok || !tokens.id_token) {
|
||||||
|
// Microsoft's AADSTS code says why (bad secret, SPA platform, redirect mismatch); keep it in the logs only.
|
||||||
|
console.error("Microsoft token exchange failed:", tokenResponse.status, tokens.error || "", String(tokens.error_description || "").split(/\r?\n/)[0]);
|
||||||
|
throw new Error("Microsoft could not verify this sign-in.");
|
||||||
|
}
|
||||||
const claims = await validateMicrosoftIdToken(tokens.id_token, pending.nonce);
|
const claims = await validateMicrosoftIdToken(tokens.id_token, pending.nonce);
|
||||||
const email = String(claims.email || claims.preferred_username || "").trim().toLowerCase();
|
const email = String(claims.email || claims.preferred_username || "").trim().toLowerCase();
|
||||||
if (!email || !ALLOWED_EMAILS.has(email)) {
|
if (!email || !ALLOWED_EMAILS.has(email)) {
|
||||||
|
|||||||
Reference in new issue
Block a user