You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

iOS Maui中Azure AD登录访问远程表时出现cannot_access_publisher_keychain错误

解决iOS MAUI应用cannot_access_publisher_keychain错误的方案

1. 修正Keychain访问组配置

你当前配置的$(AppIdentifierPrefix)com.microsoft.adalcache是ADAL库的旧分组,但MAUI项目更推荐使用MSAL(微软认证库的最新版本),对应的Keychain分组应该是$(AppIdentifierPrefix)com.microsoft.identity.client。直接替换Info.plist中的keychain-access-groups值:

<key>keychain-access-groups</key>
<array>
    <string>$(AppIdentifierPrefix)com.microsoft.identity.client</string>
</array>

如果确实还在使用ADAL,确保分组值和代码中配置一致,但强烈建议迁移到MSAL(ADAL已停止维护)。

2. 在认证代码中指定Keychain安全组

无论使用MSAL还是ADAL,都必须在初始化认证客户端时显式指定Keychain分组,否则库无法正确访问对应Keychain容器:

  • MSAL示例:
var pcaOptions = new PublicClientApplicationOptions
{
    ClientId = "你的客户端ID",
    TenantId = "你的租户ID",
    // 这里必须和Info.plist中的分组完全匹配
    KeychainSecurityGroup = $"{AppInfo.Current.AppIdentifierPrefix}com.microsoft.identity.client"
};
var pca = PublicClientApplicationBuilder.CreateWithApplicationOptions(pcaOptions)
                                       .Build();
  • ADAL示例(不推荐):
var authContext = new AuthenticationContext("你的授权地址");
authContext.KeychainGroupId = $"{AppInfo.Current.AppIdentifierPrefix}com.microsoft.adalcache";

3. 启用Xcode中的Keychain Sharing能力

MAUI项目编译时可能不会自动同步Keychain配置到Xcode,需要手动操作:

  1. 在Visual Studio中右键MAUI iOS项目,选择在Xcode中打开
  2. 在Xcode的Signing & Capabilities标签页,点击+ Capability,添加Keychain Sharing
  3. 在Keychain Sharing的Keychain Groups列表中,添加和Info.plist一致的分组值

4. 清理缓存并重新部署

  • 删除模拟器/真机上的旧应用
  • 在Visual Studio中清理项目(菜单->项目->清理)
  • 重新编译并部署到设备

额外检查

确保你的GetAuthenticationToken方法中,获取令牌后没有尝试从Keychain读取缓存令牌的逻辑出错。虽然你提到已获取有效令牌,但后续API调用时,认证库可能会尝试从Keychain加载缓存令牌,此时如果Keychain访问失败就会抛出cannot_access_publisher_keychain错误。

内容的提问来源于stack exchange,提问作者inno

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 04:30:19