iOS应用无法访问发布者钥匙链(TeamId为空)问题求助
问题:iOS下MSAL无法访问发布者钥匙链(TeamId为空)
我创建了IdentityClient,代码实现如下:
public MSAuthenticator() { IdentityClient = PublicClientApplicationBuilder .CreateWithApplicationOptions(appOptions) .WithExperimentalFeatures(true) .WithLogging(_logger) .WithIosKeychainSecurityGroup("com.microsoft.adalcache") .Build(); }
并且已向.csproj中添加自定义Entitlements.plist文件,内容如下:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>aps-environment</key> <string>development</string> <key>keychain-access-groups</key> <array> <string>$(AppIdentifierPrefix)com.microsoft.adalcache</string> </array> </dict> </plist>
运行时仍遇到错误:error_code = cannot_access_publisher_keychain
错误详情:应用无法访问iOS发布者钥匙链(TeamId为空)。这是实现同一发布者应用间单点登录(Single Sign On)的必要条件,属于iOS配置问题。
解决建议:
- 确认项目签名配置中的Team ID已正确设置:
- 在VS Code的iOS项目设置中找到签名选项,选择对应的开发团队,确保Team ID被系统正确识别并填充。
- 手动替换Entitlements.plist中的
$(AppIdentifierPrefix)为实际的Team ID(可在Apple开发者账号中查看,为10位字符串),修改后的访问组应为[你的Team ID].com.microsoft.adalcache。
- 启用钥匙链共享功能:在iOS项目的「签名与功能」设置里,开启「钥匙链共享」,并添加
[你的Team ID].com.microsoft.adalcache这个访问组。 - 确保MSAL初始化时的
WithIosKeychainSecurityGroup参数和Entitlements.plist中的访问组完全一致(包含Team ID前缀)。 - 清理项目缓存:删除项目的
bin和obj目录,重启VS Code后重新构建项目。
内容的提问来源于stack exchange,提问作者user24637963
相关产品推荐
相关产品推荐

