Skip to content

Add support for calling WithClientClaims flow for token acquisition - #3623

Merged
Travis Walker (trwalke) merged 15 commits into
masterfrom
marcinzo/idweb_custom_claims
Feb 4, 2026
Merged

Travis Walker (trwalke) merged 15 commits into
masterfrom
marcinzo/idweb_custom_claims

Conversation

@MZOLN

@MZOLN MARCIN Z (MZOLN) commented Nov 24, 2025 •

Copy link
Copy Markdown
Contributor

This pull request updates the Microsoft Identity Web library to support passing custom client assertion claims during token acquisition, and upgrades the Microsoft Identity Client dependency version. The main changes involve adding logic to extract client claims from the provided options and pass them to the underlying authentication builder methods, as well as handling serialization. Several usages of obsolete APIs are now explicitly suppressed with pragma directives.

Dependency update:

  • Upgraded the MicrosoftIdentityClientVersion from 4.77.1 to 4.82.0 in Directory.Build.props, ensuring the project uses the latest features and fixes from the Microsoft Authentication Library.

Support for custom client assertion claims:

  • Added a new helper method GetClientClaimsIfExist in TokenAcquisition.cs to extract and serialize client claims from TokenAcquisitionOptions, and integrated it into the main token acquisition flows (GetAuthenticationResultForUserAsync, GetAuthenticationResultForAppAsync, GetAuthenticationResultForWebAppWithAccountFromCacheAsync, and NotifyCertificateSelection). This enables passing custom client assertion claims to the authentication builder. [1] [2] [3] [4] [5]

API usage and code quality:

  • Suppressed compiler warnings for usage of obsolete methods (e.g., WithExtraQueryParameters) by adding pragma directives around affected calls throughout TokenAcquisition.cs. [1] [2] [3] [4] [5]

Other improvements:

  • Minor code cleanup and documentation improvements, such as fixing parameter doc comments and removing unnecessary blank lines. [1] [2]

Serialization support:

  • Added a using System.Text.Json; directive to enable JSON serialization of client claims.Add support for calling WithClientClaims flow for token acquisition

Enabling MSAL's WithClientClaims flavor of client assertions call and exposing it through IdWeb.

Comment thread src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs
@trwalke
Travis Walker (trwalke) marked this pull request as ready for review February 4, 2026 00:16
@trwalke
Travis Walker (trwalke) requested a review from a team as a code owner February 4, 2026 00:16
Comment thread src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs Outdated

Copilot AI commented Feb 4, 2026

Copy link
Copy Markdown
Contributor

Travis Walker (@trwalke) I've opened a new pull request, #3703, to work on those changes. Once the pull request is ready, I'll request review from you.

Comment thread src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs Outdated

@bgavrilMS Bogdan Gavril (bgavrilMS) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved with comments.,

Comment thread src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants