Skip to content

Bug report: unable to fetch new token using util accesstoken get #5891

Description

@milanholemans

Priority

(Medium) I'm annoyed but I'll live

Description

When using application permissions, if you want to retrieve a new access token using util accesstoken get -r graph --new, instead of fetching a new access token, CLI just retrieves a token from the cache.
When running the command in debug mode, you get the following result (check red arrow):

image

Steps to reproduce

  1. Login using an app-only context
m365 login --authType certificate --certificateFile xxxx --password yyyy --appId zzzz --tenant uuuu
  1. In Microsoft Entra ID, add a permission scope to your app registration.
  2. Fetch a new token
m365 util accesstoken get -r graph --new

The newly added scope is not included in the new token.

Expected results

To fetch a new token instead of returning one from the cache.

Actual results

Token from cache is returned.

Diagnostics

No response

CLI for Microsoft 365 version

v7.6.0

nodejs version

v20.10.0

Operating system (environment)

Windows

Shell

PowerShell

cli doctor

No response

Additional Info

Debug info:

m365 util accesstoken get -r graph --new -o text --debug
Executing command util accesstoken get with options {"options":{"resource":"graph","new":true,"output":"text","debug":true}}
Executing command as 'CLI for Microsoft 365', appId: xxxxx, tenantId: yyyyy
Access token expired. Token: eyJ0eXAiOiJKV1..., ExpiresAt: 2024-03-08T09:50:06.000Z
Retrieving new access token using certificate...
pkcs8ShroudedKeyBagkeyBags length is 1
keyBag length is 0
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Info - acquireTokenByClientCredential called
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - initializeRequestScopes called
[Fri, 08 Mar 2024 08:50:21 GMT] : [513be026-4950-4501-9b88-9d37e7368fdc] : @azure/msal-node@2.6.3 : Verbose - buildOauthClientConfiguration called
[Fri, 08 Mar 2024 08:50:21 GMT] : [513be026-4950-4501-9b88-9d37e7368fdc] : @azure/msal-node@2.6.3 : Verbose - createAuthority called
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Attempting to get cloud discovery metadata  from authority configuration
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Did not find cloud discovery metadata in the config... Attempting to get cloud discovery metadata from the hardcoded values.
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Found cloud discovery metadata from hardcoded values.
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Attempting to get endpoint metadata from authority configuration
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Did not find endpoint metadata in the config... Attempting to get endpoint metadata from the hardcoded values.
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Replacing tenant domain name xxxxxx with id {tenantid}
[Fri, 08 Mar 2024 08:50:21 GMT] : [yyyyyyyyyyyyy] : @azure/msal-node@2.6.3 : Info - Building oauth client configuration with the following authority: https://login.microsoftonline.com/xxxxxxxx/oauth2/v2.0/token.
[Fri, 08 Mar 2024 08:50:21 GMT] : [] : @azure/msal-node@2.6.3 : Verbose - Replacing tenant domain name xxxxx with id {tenantid}
[Fri, 08 Mar 2024 08:50:21 GMT] : [yyyyyyyyyy] : @azure/msal-node@2.6.3 : Verbose - Client credential client created
Response
{
  authority: 'https://login.microsoftonline.com/xxxxxxxxxx/',
  uniqueId: '',
  tenantId: '',
  scopes: [ 'https://graph.microsoft.com/.default' ],
  account: null,
  idToken: '',
  idTokenClaims: {},
  accessToken: 'eyJ0eXAiOi...',
  fromCache: true,
  expiresOn: 2024-03-08T09:50:06.000Z,
  extExpiresOn: 2024-03-08T10:50:05.000Z,
  refreshOn: undefined,
  correlationId: '513be026-4950-4501-9b88-9d37e7368fdc',
  requestId: '',
  familyId: '',
  tokenType: 'Bearer',
  state: '',
  cloudGraphHostName: '',
  msGraphHost: '',
  code: undefined,
  fromNativeBroker: false
}

eyJ0eX....

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions