iOS Maui中Azure AD登录访问远程表时出现cannot_access_publisher_keychain错误
解决iOS MAUI应用
cannot_access_publisher_keychain错误的方案 1. 修正Keychain访问组配置
你当前配置的$(AppIdentifierPrefix)com.microsoft.adalcache是ADAL库的旧分组,但MAUI项目更推荐使用MSAL(微软认证库的最新版本),对应的Keychain分组应该是$(AppIdentifierPrefix)com.microsoft.identity.client。直接替换Info.plist中的keychain-access-groups值:
<key>keychain-access-groups</key> <array> <string>$(AppIdentifierPrefix)com.microsoft.identity.client</string> </array>
如果确实还在使用ADAL,确保分组值和代码中配置一致,但强烈建议迁移到MSAL(ADAL已停止维护)。
2. 在认证代码中指定Keychain安全组
无论使用MSAL还是ADAL,都必须在初始化认证客户端时显式指定Keychain分组,否则库无法正确访问对应Keychain容器:
- MSAL示例:
var pcaOptions = new PublicClientApplicationOptions { ClientId = "你的客户端ID", TenantId = "你的租户ID", // 这里必须和Info.plist中的分组完全匹配 KeychainSecurityGroup = $"{AppInfo.Current.AppIdentifierPrefix}com.microsoft.identity.client" }; var pca = PublicClientApplicationBuilder.CreateWithApplicationOptions(pcaOptions) .Build();
- ADAL示例(不推荐):
var authContext = new AuthenticationContext("你的授权地址"); authContext.KeychainGroupId = $"{AppInfo.Current.AppIdentifierPrefix}com.microsoft.adalcache";
3. 启用Xcode中的Keychain Sharing能力
MAUI项目编译时可能不会自动同步Keychain配置到Xcode,需要手动操作:
- 在Visual Studio中右键MAUI iOS项目,选择在Xcode中打开
- 在Xcode的
Signing & Capabilities标签页,点击+ Capability,添加Keychain Sharing - 在Keychain Sharing的
Keychain Groups列表中,添加和Info.plist一致的分组值
4. 清理缓存并重新部署
- 删除模拟器/真机上的旧应用
- 在Visual Studio中清理项目(菜单->项目->清理)
- 重新编译并部署到设备
额外检查
确保你的GetAuthenticationToken方法中,获取令牌后没有尝试从Keychain读取缓存令牌的逻辑出错。虽然你提到已获取有效令牌,但后续API调用时,认证库可能会尝试从Keychain加载缓存令牌,此时如果Keychain访问失败就会抛出cannot_access_publisher_keychain错误。
内容的提问来源于stack exchange,提问作者inno
相关产品推荐
相关产品推荐

