このページは、MicrosoftのMSALチュートリアルページについて、自分が読みながら行った際に、なかなか分かりにくかったところもありましたので、なるべく丁寧に記載しています。
Microsoftのチュートリアルページはこちらです。
https://learn.microsoft.com/ja-jp/entra/identity-platform/tutorial-v2-ios
このチュートリアルの内容をxcodeとM365 Entra IDで作る内容です。
完成するとアプリからMicrosoftへの認証が行われ、ログインした状態となります。私の場合は、検証に使用しているiPhoneにMicrosoftのAuthenticatorが入っているので、Authenticatorにて認証が行われています。Authenticatorが入っていない場合は、ログインのウィンドウが表示され、ユーザー名、パスワードを入力する認証になります。
「Call Microsoft Graph API」を押します。
data:image/s3,"s3://crabby-images/0a206/0a206b10cc656c4d601df0adaa23a34af1add344" alt=""
「ロック解除」を選択します。
data:image/s3,"s3://crabby-images/12fe7/12fe79801fc21520cded4877bcbd83910a603467" alt=""
認証を行うEntra IDテナントを選択します。
data:image/s3,"s3://crabby-images/dd110/dd11089d244fe62a04242b3bdb40d9bfd9c2b8f3" alt=""
ログインに成功すると、このような画面になり、ログインしているユーザー情報が表示されます。
data:image/s3,"s3://crabby-images/b168e/b168e390ad6e92483a229401faa803fb8a2e9c63" alt=""
サインアウトをすると次のような画面になります。
data:image/s3,"s3://crabby-images/120e0/120e077f0f6832337dff91105473ba132233fc89" alt=""
Xcodeのプロジェクトを作成します。
「Create New Project」を選択します。
data:image/s3,"s3://crabby-images/73855/73855964c63236b7625b5c83e5f7dc74f75a5c2d" alt=""
「App」を選択して、「Next」をクリックします。
data:image/s3,"s3://crabby-images/079f6/079f67725cae23aba2a984fae1fbc84eb4854647" alt=""
Product Nameに作成するアプリ名を入れます。私は、「MyUikitMSAL」としました。
Teamは、ご自分のTeamを選択してください。Interfaceに「Storyboard」を選択し、「Next」をクリックします。
data:image/s3,"s3://crabby-images/ec002/ec00287e24f45c662a73877191e8678c8a4b7658" alt=""
アプリケーションを格納するフォルダを選択して、「Create」をクリックします。
data:image/s3,"s3://crabby-images/712a2/712a22f7ccb855939ddfdedbe032c96ba90f42ea" alt=""
プロジェクトが作成されました。
data:image/s3,"s3://crabby-images/3b765/3b765da546f5db830ca6f954b654d72af859c0cc" alt=""
Safariを立ち上げます。
プライベートモードでウィンドウを開きます。
data:image/s3,"s3://crabby-images/9b836/9b8368ca08e3b2cfcd84d08e3c51f96ece8fab7a" alt=""
通常モードでウィンドウを開いても構いません。会社と自宅など、複数のM365アカウントをお使いの場合、ブラウザがどちらの環境かをうまく認識しないことがあります。
その場合には、プライベートモードでウィンドウを開くと、アカウント情報が参照されず、クリアな状態となりますので、お試しください。
URLに「portal.office.com」を入力し、ページを開きます。
data:image/s3,"s3://crabby-images/4facc/4facc7e89b9d9f1971844fcb0670364931cebeb5" alt=""
ユーザー名、パスワードを入力し、サインインします。
data:image/s3,"s3://crabby-images/7e06a/7e06a672ab53909b8c4d51a4ef94ce8d9721ff4a" alt=""
data:image/s3,"s3://crabby-images/7d955/7d955e6ca48f58c9e21378838cfd28a6bff1900c" alt=""
data:image/s3,"s3://crabby-images/17a3d/17a3d001e913cab0aec587484b56ee911664ddb7" alt=""
M365にサインインができたら、管理センターを開きます。
data:image/s3,"s3://crabby-images/ea25f/ea25f8a8ef80fbf9bf3a535be97225f4db2a792a" alt=""
管理センターのメニューから「ID」をクリックします。
data:image/s3,"s3://crabby-images/aa40c/aa40c487b1cd868861628c98fb63d79e5fbeeb9a" alt=""
Entra管理センターのメニューから、アプリケーションを選択し、「アプリの登録」をクリックします。
data:image/s3,"s3://crabby-images/12c40/12c40617485b58f0ba24b286497e161bf0072e0a" alt=""
「新規登録」をクリックします。
data:image/s3,"s3://crabby-images/e632d/e632da2abfed6a5c388216ddb52b8a14a4cffe0d" alt=""
アプリケーションの名前を入力します。この記事と同じように作る場合は、「MyUikitMSAL」を入力してください。
サポートされているアカウントの種類に、「任意の組織ディレクトリ内のアカウント(任意のMicrosoft Entra ID テナント – マルチテナント)と個人用のMicrosoftアカウント(Skype、Xboxなど)」を選択します。
「登録」をクリックします。
data:image/s3,"s3://crabby-images/89cf2/89cf23e81447afe8843ec284bb5d17fabed38410" alt=""
続いてプラットフォームの追加を行います。「認証」をクリックします。
data:image/s3,"s3://crabby-images/f6b39/f6b3968823742bb0bc4e92f009c5953bd45b9d19" alt=""
「プラットフォームを追加」をクリックします。
data:image/s3,"s3://crabby-images/23841/2384170118310f480ad9cee3549abbf6e00f1c44" alt=""
「iOS または macOS」をクリックします。
data:image/s3,"s3://crabby-images/a658a/a658aa778196b8786b8532370465047baafe8813" alt=""
バンドルIDを入力し、「構成」をクリックします。
data:image/s3,"s3://crabby-images/fab66/fab66f205158fa63614f33d894e8af4e326fad04" alt=""
バンドルIDは Xcodeで確認します。
プロジェクトのTARGETSを選択し、Signing & Capabilities を選択すると、Bundle Identifierが表示されます。
これがバンドルIDです。
構成が完了すると、MSAL構成が表示されます。こちらの値をXcodeのプログラムに埋め込みますので、メモ帳にコピーするか、このページを開いたままにしておきましょう。
data:image/s3,"s3://crabby-images/b07c8/b07c8951c0fd8b5a6076cfd4e7e6cae60442299d" alt=""
これでM365 Entra IDへのアプリ登録は完了です。
data:image/s3,"s3://crabby-images/0ab34/0ab34845238b71e1a7fe60f9f15b9c42afebfe1c" alt=""
XcodeにMSALフレームワークを追加する方法として、ここではXcodeのAdd Package Dependenciesを利用する方法で行っています。他の方法として、CocoaPods、Carthageを利用する方法があります。
Fileメニューから「Add Package Dependencies」を選択します。
data:image/s3,"s3://crabby-images/5cb78/5cb78b138229c1f29709da236827a8e140c7bcd4" alt=""
右上にURL「https://github.com/AzureAD/microsoft-authentication-library-for-objc」を入力します。
Microsoft Authentication Libraryが表示されますので、「Add Package」をクリックします。
data:image/s3,"s3://crabby-images/2cd01/2cd01270ddf4feee96955a83354444942ef0450a" alt=""
パッケージのインストールが始まります。途中、パスワードを聞かれたら、PCにログインしているパスワードを入力します。
data:image/s3,"s3://crabby-images/49d5c/49d5c9725997b1009ff7229f6f9540a76c653aa3" alt=""
「Add Package」をクリックします。
data:image/s3,"s3://crabby-images/66fe3/66fe3809baf5c041f1f94ea1e9b916ab711577d1" alt=""
MSALパッケージが追加されました。Xcodeのプロジェクト上でMSALが追加されたことを確認できます。
data:image/s3,"s3://crabby-images/1a509/1a509000d4cf492920918591e54aab986aa9e95b" alt=""
ViewController.swift、 AppDelegate.swift、SceneDelegate.swiftに、import MSALを追加します。
・ViewController.swift
import UIKit
import MSAL
class ViewController: UIViewController {
override func viewDidLoad() {
super.viewDidLoad()
// Do any additional setup after loading the view.
}
}
・AppDelegate.swift
import UIKit
import MSAL
@main
class AppDelegate: UIResponder, UIApplicationDelegate {
func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey: Any]?) -> Bool {
// Override point for customization after application launch.
return true
}
// MARK: UISceneSession Lifecycle
func application(_ application: UIApplication, configurationForConnecting connectingSceneSession: UISceneSession, options: UIScene.ConnectionOptions) -> UISceneConfiguration {
// Called when a new scene session is being created.
// Use this method to select a configuration to create the new scene with.
return UISceneConfiguration(name: "Default Configuration", sessionRole: connectingSceneSession.role)
}
func application(_ application: UIApplication, didDiscardSceneSessions sceneSessions: Set<UISceneSession>) {
// Called when the user discards a scene session.
// If any sessions were discarded while the application was not running, this will be called shortly after application:didFinishLaunchingWithOptions.
// Use this method to release any resources that were specific to the discarded scenes, as they will not return.
}
}
・SceneDelegate.swift
import UIKit
import MSAL
class SceneDelegate: UIResponder, UIWindowSceneDelegate {
var window: UIWindow?
func scene(_ scene: UIScene, willConnectTo session: UISceneSession, options connectionOptions: UIScene.ConnectionOptions) {
// Use this method to optionally configure and attach the UIWindow `window` to the provided UIWindowScene `scene`.
// If using a storyboard, the `window` property will automatically be initialized and attached to the scene.
// This delegate does not imply the connecting scene or session are new (see `application:configurationForConnectingSceneSession` instead).
guard let _ = (scene as? UIWindowScene) else { return }
}
func sceneDidDisconnect(_ scene: UIScene) {
// Called as the scene is being released by the system.
// This occurs shortly after the scene enters the background, or when its session is discarded.
// Release any resources associated with this scene that can be re-created the next time the scene connects.
// The scene may re-connect later, as its session was not necessarily discarded (see `application:didDiscardSceneSessions` instead).
}
func sceneDidBecomeActive(_ scene: UIScene) {
// Called when the scene has moved from an inactive state to an active state.
// Use this method to restart any tasks that were paused (or not yet started) when the scene was inactive.
}
func sceneWillResignActive(_ scene: UIScene) {
// Called when the scene will move from an active state to an inactive state.
// This may occur due to temporary interruptions (ex. an incoming phone call).
}
func sceneWillEnterForeground(_ scene: UIScene) {
// Called as the scene transitions from the background to the foreground.
// Use this method to undo the changes made on entering the background.
}
func sceneDidEnterBackground(_ scene: UIScene) {
// Called as the scene transitions from the foreground to the background.
// Use this method to save data, release shared resources, and store enough scene-specific state information
// to restore the scene back to its current state.
}
}
ViewController.swift に MSAL構成を追加します。MSAL構成は、M365にアプリケーション登録し、プラットフォーム追加した際の情報です。
・ViewController.swift
import UIKit
import MSAL
class ViewController: UIViewController {
// Update the below to your client ID. The below is for running the demo only
let kClientID = "ここにあなたのクライアントIDを記載"
let kGraphEndpoint = "https://graph.microsoft.com/" // the Microsoft Graph endpoint
let kAuthority = "https://login.microsoftonline.com/common" // this authority allows a personal Microsoft account and a work or school account in any organization's Azure AD tenant to sign in
let kScopes: [String] = ["user.read"] // request permission to read the profile of the signed-in user
var accessToken = String()
var applicationContext : MSALPublicClientApplication?
var webViewParameters : MSALWebviewParameters?
var currentAccount: MSALAccount?
let kRedirectUri = "msauth.starmanblog.MyUikitMSAL://auth"
override func viewDidLoad() {
super.viewDidLoad()
// Do any additional setup after loading the view.
}
}
Xcodeのキーチェイングループに com.microsoft.adalcache を追加します。
TARGETS、Signing&Capabilitiesを選択し、「Capability」をクリックします。
data:image/s3,"s3://crabby-images/2ab1c/2ab1cc19a26a2ab61e7311ba5c4d6e302f5d981d" alt=""
表示されたCapabilitiesの中から、「Keychain Sharing」をダブルクリックします。
data:image/s3,"s3://crabby-images/d5e5f/d5e5f5be75d2ffb913bd04faad158c6eea2e2b94" alt=""
Keychain Sharingが追加されます。「+」をクリックします。
data:image/s3,"s3://crabby-images/7d7fb/7d7fbae035fe0d7bf076c7e7fad5046afdb5afd9" alt=""
Keychain Groupsに「com.microsoft.adalcache」を追加します。
data:image/s3,"s3://crabby-images/c3d22/c3d2222d5e65ce2c2ba5a82e1cf4da50aabe931c" alt=""
info.plistにMSAL認証で必要な記載を追加します。
info.plistファイルは、Xcodeでプロジェクトを作成する際に、InterfaceにStoryboardを選択した際に、自動的に作成されています。
data:image/s3,"s3://crabby-images/9ce1d/9ce1da6fcd9ec1d437eb7dd2b5e66692ec62b7e7" alt=""
最初プロパティ値で表示されています。XMLで記載を追加するため、ソースコード表示にします。
info.plistを右クリックし、Open Asから「Source Code」を選択します。
data:image/s3,"s3://crabby-images/b7e64/b7e6461e23cd240127fd8ca44a66352509707b38" alt=""
XML表記で表示されました。
data:image/s3,"s3://crabby-images/c0772/c077284592f37513e315c7f5eb4335d18a9c4ba0" alt=""
赤枠の部分に記載を追加します。
data:image/s3,"s3://crabby-images/5f43b/5f43bd71aaffa5de93aa81f345b249d3337f0342" alt=""
info.plistは次のようになります。黄色の線の部分が追加したところです。
「msauth.starmanblog.MyUikitMSAL」の部分を自分のバンドルIDを記載します。
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>UIApplicationSceneManifest</key>
<dict>
<key>UIApplicationSupportsMultipleScenes</key>
<false/>
<key>UISceneConfigurations</key>
<dict>
<key>UIWindowSceneSessionRoleApplication</key>
<array>
<dict>
<key>UISceneConfigurationName</key>
<string>Default Configuration</string>
<key>UISceneDelegateClassName</key>
<string>$(PRODUCT_MODULE_NAME).SceneDelegate</string>
<key>UISceneStoryboardFile</key>
<string>Main</string>
</dict>
</array>
</dict>
</dict>
<key>CFBundleURLTypes</key>
<array>
<dict>
<key>CFBundleURLSchemes</key>
<array>
<string>msauth.starmanblog.MyUikitMSAL</string>
</array>
</dict>
</array>
<key>LSApplicationQueriesSchemes</key>
<array>
<string>msauthv2</string>
<string>msauthv3</string>
</array>
</dict>
</plist>
このあとは、チュートリアルに沿って、ViewController.swift、AppDelegate.swift、SceneDelegate.swiftに記載を追加します。
具体的には、チュートリアルの次のトピックに書かれている内容です。
- アプリの UI の作成
- MSAL の使用
- サインイン コールバックを処理する (iOS のみ)
- トークンの取得
- 対話形式でのユーザー トークンの取得
- トークンの自動取得
- Microsoft Graph API を呼び出す
- サインアウトに MSAL を使用する
- ヘルパー メソッドの追加
- iOS の場合のみ: 追加のデバイス情報を取得する
完成するViewController.swift、AppDelegate.swift、SceneDelegate.swiftは次のようになります。
・ViewController.swift
import UIKit
import MSAL
class ViewController: UIViewController {
// Update the below to your client ID. The below is for running the demo only
let kClientID = "ここにあなたのクライアントIDを記載"
let kGraphEndpoint = "https://graph.microsoft.com/" // the Microsoft Graph endpoint
let kAuthority = "https://login.microsoftonline.com/common" // this authority allows a personal Microsoft account and a work or school account in any organization's Azure AD tenant to sign in
let kScopes: [String] = ["user.read"] // request permission to read the profile of the signed-in user
var accessToken = String()
var applicationContext : MSALPublicClientApplication?
var webViewParameters : MSALWebviewParameters?
var currentAccount: MSALAccount?
let kRedirectUri = "msauth.starmanblog.MyUikitMSAL://auth"
override func viewDidLoad() {
super.viewDidLoad()
initUI()
do {
try self.initMSAL()
} catch let error {
self.updateLogging(text: "Unable to create Application Context \(error)")
}
self.loadCurrentAccount()
self.platformViewDidLoadSetup()
}
var loggingText: UITextView!
var signOutButton: UIButton!
var callGraphButton: UIButton!
var usernameLabel: UILabel!
func initUI() {
usernameLabel = UILabel()
usernameLabel.translatesAutoresizingMaskIntoConstraints = false
usernameLabel.text = ""
usernameLabel.textColor = .darkGray
usernameLabel.textAlignment = .right
self.view.addSubview(usernameLabel)
usernameLabel.topAnchor.constraint(equalTo: view.topAnchor, constant: 50.0).isActive = true
usernameLabel.rightAnchor.constraint(equalTo: view.rightAnchor, constant: -10.0).isActive = true
usernameLabel.widthAnchor.constraint(equalToConstant: 300.0).isActive = true
usernameLabel.heightAnchor.constraint(equalToConstant: 50.0).isActive = true
// Add call Graph button
callGraphButton = UIButton()
callGraphButton.translatesAutoresizingMaskIntoConstraints = false
callGraphButton.setTitle("Call Microsoft Graph API", for: .normal)
callGraphButton.setTitleColor(.blue, for: .normal)
callGraphButton.addTarget(self, action: #selector(callGraphAPI(_:)), for: .touchUpInside)
self.view.addSubview(callGraphButton)
callGraphButton.centerXAnchor.constraint(equalTo: view.centerXAnchor).isActive = true
callGraphButton.topAnchor.constraint(equalTo: view.topAnchor, constant: 120.0).isActive = true
callGraphButton.widthAnchor.constraint(equalToConstant: 300.0).isActive = true
callGraphButton.heightAnchor.constraint(equalToConstant: 50.0).isActive = true
// Add sign out button
signOutButton = UIButton()
signOutButton.translatesAutoresizingMaskIntoConstraints = false
signOutButton.setTitle("Sign Out", for: .normal)
signOutButton.setTitleColor(.blue, for: .normal)
signOutButton.setTitleColor(.gray, for: .disabled)
signOutButton.addTarget(self, action: #selector(signOut(_:)), for: .touchUpInside)
self.view.addSubview(signOutButton)
signOutButton.centerXAnchor.constraint(equalTo: view.centerXAnchor).isActive = true
signOutButton.topAnchor.constraint(equalTo: callGraphButton.bottomAnchor, constant: 10.0).isActive = true
signOutButton.widthAnchor.constraint(equalToConstant: 150.0).isActive = true
signOutButton.heightAnchor.constraint(equalToConstant: 50.0).isActive = true
let deviceModeButton = UIButton()
deviceModeButton.translatesAutoresizingMaskIntoConstraints = false
deviceModeButton.setTitle("Get device info", for: .normal);
deviceModeButton.setTitleColor(.blue, for: .normal);
deviceModeButton.addTarget(self, action: #selector(getDeviceMode(_:)), for: .touchUpInside)
self.view.addSubview(deviceModeButton)
deviceModeButton.centerXAnchor.constraint(equalTo: view.centerXAnchor).isActive = true
deviceModeButton.topAnchor.constraint(equalTo: signOutButton.bottomAnchor, constant: 10.0).isActive = true
deviceModeButton.widthAnchor.constraint(equalToConstant: 150.0).isActive = true
deviceModeButton.heightAnchor.constraint(equalToConstant: 50.0).isActive = true
// Add logging textfield
loggingText = UITextView()
loggingText.isUserInteractionEnabled = false
loggingText.translatesAutoresizingMaskIntoConstraints = false
self.view.addSubview(loggingText)
loggingText.topAnchor.constraint(equalTo: deviceModeButton.bottomAnchor, constant: 10.0).isActive = true
loggingText.leftAnchor.constraint(equalTo: self.view.leftAnchor, constant: 10.0).isActive = true
loggingText.rightAnchor.constraint(equalTo: self.view.rightAnchor, constant: -10.0).isActive = true
loggingText.bottomAnchor.constraint(equalTo: self.view.bottomAnchor, constant: 10.0).isActive = true
}
func platformViewDidLoadSetup() {
NotificationCenter.default.addObserver(self,
selector: #selector(appCameToForeGround(notification:)),
name: UIApplication.willEnterForegroundNotification,
object: nil)
}
@objc func appCameToForeGround(notification: Notification) {
self.loadCurrentAccount()
}
func initMSAL() throws {
guard let authorityURL = URL(string: kAuthority) else {
self.updateLogging(text: "Unable to create authority URL")
return
}
let authority = try MSALAADAuthority(url: authorityURL)
let msalConfiguration = MSALPublicClientApplicationConfig(clientId: kClientID, redirectUri: nil, authority: authority)
self.applicationContext = try MSALPublicClientApplication(configuration: msalConfiguration)
self.initWebViewParams()
}
func initWebViewParams() {
self.webViewParameters = MSALWebviewParameters(authPresentationViewController: self)
}
func getGraphEndpoint() -> String {
return kGraphEndpoint.hasSuffix("/") ? (kGraphEndpoint + "v1.0/me/") : (kGraphEndpoint + "/v1.0/me/");
}
@objc func callGraphAPI(_ sender: AnyObject) {
self.loadCurrentAccount { (account) in
guard let currentAccount = account else {
// We check to see if we have a current logged in account.
// If we don't, then we need to sign someone in.
self.acquireTokenInteractively()
return
}
self.acquireTokenSilently(currentAccount)
}
}
typealias AccountCompletion = (MSALAccount?) -> Void
func loadCurrentAccount(completion: AccountCompletion? = nil) {
guard let applicationContext = self.applicationContext else { return }
let msalParameters = MSALParameters()
msalParameters.completionBlockQueue = DispatchQueue.main
applicationContext.getCurrentAccount(with: msalParameters, completionBlock: { (currentAccount, previousAccount, error) in
if let error = error {
self.updateLogging(text: "Couldn't query current account with error: \(error)")
return
}
if let currentAccount = currentAccount {
self.updateLogging(text: "Found a signed in account \(String(describing: currentAccount.username)). Updating data for that account...")
self.updateCurrentAccount(account: currentAccount)
if let completion = completion {
completion(self.currentAccount)
}
return
}
self.updateLogging(text: "Account signed out. Updating UX")
self.accessToken = ""
self.updateCurrentAccount(account: nil)
if let completion = completion {
completion(nil)
}
})
}
func acquireTokenInteractively() {
guard let applicationContext = self.applicationContext else { return }
guard let webViewParameters = self.webViewParameters else { return }
// #1
let parameters = MSALInteractiveTokenParameters(scopes: kScopes, webviewParameters: webViewParameters)
parameters.promptType = .selectAccount
// #2
applicationContext.acquireToken(with: parameters) { (result, error) in
// #3
if let error = error {
self.updateLogging(text: "Could not acquire token: \(error)")
return
}
guard let result = result else {
self.updateLogging(text: "Could not acquire token: No result returned")
return
}
// #4
self.accessToken = result.accessToken
self.updateLogging(text: "Access token is \(self.accessToken)")
self.updateCurrentAccount(account: result.account)
self.getContentWithToken()
}
}
func acquireTokenSilently(_ account : MSALAccount!) {
guard let applicationContext = self.applicationContext else { return }
/**
Acquire a token for an existing account silently
- forScopes: Permissions you want included in the access token received
in the result in the completionBlock. Not all scopes are
guaranteed to be included in the access token returned.
- account: An account object that we retrieved from the application object before that the
authentication flow will be locked down to.
- completionBlock: The completion block that will be called when the authentication
flow completes, or encounters an error.
*/
let parameters = MSALSilentTokenParameters(scopes: kScopes, account: account)
applicationContext.acquireTokenSilent(with: parameters) { (result, error) in
if let error = error {
let nsError = error as NSError
// interactionRequired means we need to ask the user to sign-in. This usually happens
// when the user's Refresh Token is expired or if the user has changed their password
// among other possible reasons.
if (nsError.domain == MSALErrorDomain) {
if (nsError.code == MSALError.interactionRequired.rawValue) {
DispatchQueue.main.async {
self.acquireTokenInteractively()
}
return
}
}
self.updateLogging(text: "Could not acquire token silently: \(error)")
return
}
guard let result = result else {
self.updateLogging(text: "Could not acquire token: No result returned")
return
}
self.accessToken = result.accessToken
self.updateLogging(text: "Refreshed Access token is \(self.accessToken)")
self.updateSignOutButton(enabled: true)
self.getContentWithToken()
}
}
func getContentWithToken() {
// Specify the Graph API endpoint
let graphURI = getGraphEndpoint()
let url = URL(string: graphURI)
var request = URLRequest(url: url!)
// Set the Authorization header for the request. We use Bearer tokens, so we specify Bearer + the token we got from the result
request.setValue("Bearer \(self.accessToken)", forHTTPHeaderField: "Authorization")
URLSession.shared.dataTask(with: request) { data, response, error in
if let error = error {
self.updateLogging(text: "Couldn't get graph result: \(error)")
return
}
guard let result = try? JSONSerialization.jsonObject(with: data!, options: []) else {
self.updateLogging(text: "Couldn't deserialize result JSON")
return
}
self.updateLogging(text: "Result from Graph: \(result))")
}.resume()
}
@objc func signOut(_ sender: AnyObject) {
guard let applicationContext = self.applicationContext else { return }
guard let account = self.currentAccount else { return }
do {
/**
Removes all tokens from the cache for this application for the provided account
- account: The account to remove from the cache
*/
let signoutParameters = MSALSignoutParameters(webviewParameters: self.webViewParameters!)
signoutParameters.signoutFromBrowser = false // set this to true if you also want to signout from browser or webview
applicationContext.signout(with: account, signoutParameters: signoutParameters, completionBlock: {(success, error) in
if let error = error {
self.updateLogging(text: "Couldn't sign out account with error: \(error)")
return
}
self.updateLogging(text: "Sign out completed successfully")
self.accessToken = ""
self.updateCurrentAccount(account: nil)
})
}
}
func updateLogging(text : String) {
if Thread.isMainThread {
self.loggingText.text = text
} else {
DispatchQueue.main.async {
self.loggingText.text = text
}
}
}
func updateSignOutButton(enabled : Bool) {
if Thread.isMainThread {
self.signOutButton.isEnabled = enabled
} else {
DispatchQueue.main.async {
self.signOutButton.isEnabled = enabled
}
}
}
func updateAccountLabel() {
guard let currentAccount = self.currentAccount else {
self.usernameLabel.text = "Signed out"
return
}
self.usernameLabel.text = currentAccount.username
}
func updateCurrentAccount(account: MSALAccount?) {
self.currentAccount = account
self.updateAccountLabel()
self.updateSignOutButton(enabled: account != nil)
}
@objc func getDeviceMode(_ sender: AnyObject) {
if #available(iOS 13.0, *) {
self.applicationContext?.getDeviceInformation(with: nil, completionBlock: { (deviceInformation, error) in
guard let deviceInfo = deviceInformation else {
self.updateLogging(text: "Device info not returned. Error: \(String(describing: error))")
return
}
let isSharedDevice = deviceInfo.deviceMode == .shared
let modeString = isSharedDevice ? "shared" : "private"
self.updateLogging(text: "Received device info. Device is in the \(modeString) mode.")
})
} else {
self.updateLogging(text: "Running on older iOS. GetDeviceInformation API is unavailable.")
}
}
}
・AppDelegate.swift
import UIKit
import MSAL
@main
class AppDelegate: UIResponder, UIApplicationDelegate {
func application(_ application: UIApplication, didFinishLaunchingWithOptions launchOptions: [UIApplication.LaunchOptionsKey: Any]?) -> Bool {
// Override point for customization after application launch.
return true
}
// MARK: UISceneSession Lifecycle
func application(_ application: UIApplication, configurationForConnecting connectingSceneSession: UISceneSession, options: UIScene.ConnectionOptions) -> UISceneConfiguration {
// Called when a new scene session is being created.
// Use this method to select a configuration to create the new scene with.
return UISceneConfiguration(name: "Default Configuration", sessionRole: connectingSceneSession.role)
}
func application(_ application: UIApplication, didDiscardSceneSessions sceneSessions: Set<UISceneSession>) {
// Called when the user discards a scene session.
// If any sessions were discarded while the application was not running, this will be called shortly after application:didFinishLaunchingWithOptions.
// Use this method to release any resources that were specific to the discarded scenes, as they will not return.
}
// Append for MSAL
// Inside AppDelegate...
func application(_ app: UIApplication, open url: URL, options: [UIApplication.OpenURLOptionsKey : Any] = [:]) -> Bool {
return MSALPublicClientApplication.handleMSALResponse(url, sourceApplication: options[UIApplication.OpenURLOptionsKey.sourceApplication] as? String)
}
}
・SceneDelegate.swift
import UIKit
import MSAL
class SceneDelegate: UIResponder, UIWindowSceneDelegate {
var window: UIWindow?
func scene(_ scene: UIScene, willConnectTo session: UISceneSession, options connectionOptions: UIScene.ConnectionOptions) {
// Use this method to optionally configure and attach the UIWindow `window` to the provided UIWindowScene `scene`.
// If using a storyboard, the `window` property will automatically be initialized and attached to the scene.
// This delegate does not imply the connecting scene or session are new (see `application:configurationForConnectingSceneSession` instead).
guard let _ = (scene as? UIWindowScene) else { return }
}
func sceneDidDisconnect(_ scene: UIScene) {
// Called as the scene is being released by the system.
// This occurs shortly after the scene enters the background, or when its session is discarded.
// Release any resources associated with this scene that can be re-created the next time the scene connects.
// The scene may re-connect later, as its session was not necessarily discarded (see `application:didDiscardSceneSessions` instead).
}
func sceneDidBecomeActive(_ scene: UIScene) {
// Called when the scene has moved from an inactive state to an active state.
// Use this method to restart any tasks that were paused (or not yet started) when the scene was inactive.
}
func sceneWillResignActive(_ scene: UIScene) {
// Called when the scene will move from an active state to an inactive state.
// This may occur due to temporary interruptions (ex. an incoming phone call).
}
func sceneWillEnterForeground(_ scene: UIScene) {
// Called as the scene transitions from the background to the foreground.
// Use this method to undo the changes made on entering the background.
}
func sceneDidEnterBackground(_ scene: UIScene) {
// Called as the scene transitions from the foreground to the background.
// Use this method to save data, release shared resources, and store enough scene-specific state information
// to restore the scene back to its current state.
}
// Append for MSAL
func scene(_ scene: UIScene, openURLContexts URLContexts: Set<UIOpenURLContext>) {
guard let urlContext = URLContexts.first else {
return
}
let url = urlContext.url
let sourceApp = urlContext.options.sourceApplication
MSALPublicClientApplication.handleMSALResponse(url, sourceApplication: sourceApp)
}
}
あとはアプリを実行して、動作を確認してください。
data:image/s3,"s3://crabby-images/88f94/88f94156304f7fdfe7b7713d9100a4a2d754b6cb" alt=""
成功すると次のような画面が立ち上がります。
data:image/s3,"s3://crabby-images/6adb1/6adb177d5e8c817bbfe4e6f18280aaa3814bc730" alt=""
シミュレータで実行できたあと、手持ちのiPhoneで実行したところ、Microsoft Authenticator(Broker)との連携がうまくできずエラーになりました。こちらの記事を参考にSceneDelegateに追加したところ、動くようになりました。
チュートリアルの中のXcode11ならという記載のところだったので、コードに追加していなかったことが原因でした。
上で紹介したコードには、すでに入っていますので、大丈夫です。
次は、uikitにかわり、swift ui で実行できるといいなと考えとります。それでは。