Microsoft Graph Toolkit Microsoft Teams Msal2 Provider
The `@vonrehberg.consulting/mgt-teams-msal2-providerpackage exposes the
TeamsMsal2Providerclass to be used inside your Microsoft Teams tab applications to authenticate users, to call Microsoft Graph, and to power the Microsoft Graph Toolkit components. The provider is built on top of [msal-browser](https://github.com/AzureAD/microsoft-authentication-library-for-js/tree/dev/lib/msal-browser) and supports both the interactive sign in flow on the client and Single Sign-On (SSO) flow via your own backend. SSO mode is enabled by setting
ssoUrl\
sso-url` and requires a backend service to handle the on-behalf-of flow.
See the full documentation of the TeamsMsal2Provider
The Microsoft Graph Toolkit (mgt) library is a collection of authentication providers and UI components powered by Microsoft Graph.
Usage
The TeamsMsal2Provider requires the usage of the Microsoft Teams SDK which is not automatically installed.
Install the packages
npm install @microsoft/teams-js @vonrehberg.consulting/mgt-element @vonrehberg.consulting/mgt-teams-msal2-provider
Before initializing the provider, create a new page in your application (ex: https://mydomain.com/auth) that will handle the auth redirect. Call the
handleAuth
function to handle all client side auth or permission consent.import * as MicrosoftTeams from "@microsoft/teams-js/dist/MicrosoftTeams"; import {TeamsMsal2Provider} from '@vonrehberg.consulting/mgt-teams-msal2-provider'; TeamsMsal2Provider.microsoftTeamsLib = MicrosoftTeams; TeamsMsal2Provider.handleAuth();
Initialize the provider in your main code (not on your auth page). The provider can be used in "client side auth" mode or SSO mode. SSO mode is enabled by setting
ssoUrl
\sso-url
and requires a backend service to handle the on-behalf-of flow.import {Providers} from '@vonrehberg.consulting/mgt-element'; import {TeamsMsal2Provider} from '@vonrehberg.consulting/mgt-teams-msal2-provider'; import * as MicrosoftTeams from "@microsoft/teams-js/dist/MicrosoftTeams"; TeamsMsal2Provider.microsoftTeamsLib = MicrosoftTeams; Providers.globalProvider = new TeamsMsal2Provider({ clientId: string; authPopupUrl: string; // ex: "https://mydomain.com/auth" or "/auth" scopes?: string[]; msalOptions?: Configuration; ssoUrl?: string; // ex: '/api/token', autoConsent?: boolean, httpMethod: HttpMethod; //ex HttpMethod.POST })
Alternatively, initialize the provider in html (only
client-id
andauth-popup-url
is required):<script type="module" src="../node_modules/@vonrehberg.consulting/mgt-teams-provider/dist/es6/index.js" /> <mgt-teams-msal2-provider client-id="<YOUR_CLIENT_ID>" auth-popup-url="/AUTH-PATH" scopes="user.read,people.read..." authority="" sso-url="/api/token" http-method="POST"> ></mgt-teams-provider>
See provider usage documentation to learn about how to use the providers with the mgt components, to sign in/sign out, get access tokens, call Microsoft Graph, and more.