Improve IDW10109 error handling for credential loading failures#3946
Merged
Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR improves debuggability of IDW10109 (“No credential could be loaded”) by preserving the original credential-loading exception(s) as InnerException (or AggregateException) so callers can programmatically inspect MSAL/AADSTS failures, and removes now-redundant logging logic.
Changes:
- Preserve original credential-loading failures as
InnerExceptionwhen throwing IDW10109 fromCredentialsProvider. - Update IDW10109 text to cover signed assertion/FIC scenarios; remove dead
catchinTokenAcquisitionand an unused duplicate error constant. - Add unit tests for single vs. multiple failures; ignore repo-root
Temp/MSBuild temp output via.gitignore.
Reviewed changes
Copilot reviewed 5 out of 6 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| tests/Microsoft.Identity.Web.Test/Certificates/WithClientCredentialsTests.cs | Adds tests asserting IDW10109 preserves inner exception(s) and includes updated guidance text. |
| src/Microsoft.Identity.Web.TokenAcquisition/TokenAcquisition.cs | Removes unreachable IDW10109-specific catch/logging to avoid dead code and double logging. |
| src/Microsoft.Identity.Web.TokenAcquisition/IDWebErrorMessage.cs | Updates the IDW10109 message to cover signed assertion/FIC failures and point to inner exception details. |
| src/Microsoft.Identity.Web.TokenAcquisition/CredentialsProvider.cs | Collects credential-loading exceptions and attaches them as InnerException (or AggregateException) on IDW10109. |
| src/Microsoft.Identity.Web.Certificate/CertificateErrorMessage.cs | Removes an unused duplicate IDW10109 constant. |
| .gitignore | Ignores repo-root Temp/ directory created by newer SDK/MSBuild temp output. |
bgavrilMS
approved these changes
Jul 15, 2026
neha-bhargava
approved these changes
Jul 15, 2026
gladjohn
approved these changes
Jul 15, 2026
neha-bhargava
approved these changes
Jul 15, 2026
This was referenced Jul 17, 2026
Merged
Closed
Open
Open
Merged
This was referenced Jul 20, 2026
Closed
Open
Merged
github-actions Bot
pushed a commit
to EelcoLos/nx-tinkering
that referenced
this pull request
Jul 21, 2026
Pinned [Microsoft.Identity.Web](https://github.com/AzureAD/microsoft-identity-web) at 4.13.2. <details> <summary>Release notes</summary> _Sourced from [Microsoft.Identity.Web's releases](https://github.com/AzureAD/microsoft-identity-web/releases)._ ## 4.13.2 ## What's Changed * Apply reserved-header handling on the request-clone path and cover all X-MS-TOKEN- headers by @iNinja in AzureAD/microsoft-identity-web#3915 * Restore independent PR pipeline + pool-aware MI identity + net462/472 unit tests by @iarekk in AzureAD/microsoft-identity-web#3935 * Post-release 4.13.0: changelog and public API shipped move by @neha-bhargava in AzureAD/microsoft-identity-web#3937 * Remove redundant 'Run unit tests' GitHub Action by @iarekk in AzureAD/microsoft-identity-web#3939 * Apply consistent redirect-URI validation on AccountController.SignIn by @iNinja in AzureAD/microsoft-identity-web#3940 * Fix duplicate logging of MsalUiRequiredException (in-repo copy of #3910) by @iarekk in AzureAD/microsoft-identity-web#3941 * Use MSAL's recent UserFIC API for agentic flows by @Avery-Dunn in AzureAD/microsoft-identity-web#3842 * Restore CustomizeHttpRequestMessage to run after the authorization header by @neha-bhargava in AzureAD/microsoft-identity-web#3943 * Bump Microsoft.IdentityModel.Tokens.Saml from 5.7.0 to 8.19.1 by @dependabot[bot] in AzureAD/microsoft-identity-web#3909 * Revert #3909: keep OWIN Saml/WsFederation on 5.7.0 by @iarekk in AzureAD/microsoft-identity-web#3944 * Bump Microsoft.Identity.Abstractions from 12.4.0 to 12.5.0 by @neha-bhargava in AzureAD/microsoft-identity-web#3947 * Add OnBeforeAuthHeaderCreation / OnAfterAuthHeaderCreation hooks to DownstreamApi by @neha-bhargava in AzureAD/microsoft-identity-web#3942 * Update IdentityModelV5Version and SamlPackageVersion to 5.7.1 in proj… by @trwalke in AzureAD/microsoft-identity-web#3950 * Rename retired MSALMSIV2 agent pool to MISEManagedIdentity by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3949 * Improve IDW10109 error handling for credential loading failures by @Avery-Dunn in AzureAD/microsoft-identity-web#3946 * Bump MSAL dependencies to 4.86.1 in central props by @gladjohn with @Copilot in AzureAD/microsoft-identity-web#3953 * Bump the notsecurity group with 3 updates by @dependabot[bot] in AzureAD/microsoft-identity-web#3954 **Full Changelog**: AzureAD/microsoft-identity-web@4.13.0...4.13.2 Commits viewable in [compare view](AzureAD/microsoft-identity-web@4.13.0...4.13.2). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This was referenced Jul 21, 2026
Closed
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When credential loading fails in
CredentialsProvider(e.g., a Federated Identity Credential exchange returns an AADSTS error), the original exception is discarded. The thrownArgumentException(IDW10109) includes the exception text in its message string but does not setInnerException, so callers cannot programmatically inspect the original error. The error text also implies the root cause is about the certificate and Managed Identity scenarios, but the exception catches a much broader range of errors (such as FIC/signed assertion scenarios).Additionally, a
catch (ArgumentException ex) when (ex.Message == ...)guard inTokenAcquisition.BuildConfidentialClientApplicationAsyncused exact string equality against an IDW10109 error message constant. BecauseCredentialsProviderappends detail text andArgumentExceptionadds a parameter name suffix, the guard never matched, making it dead code. The outercatch (Exception ex)already logs and rethrows all errors from this method, so if it wasn't dead code it'd be logged twice unnecessarily.Changes
Inner exception preservation (
CredentialsProvider.cs)Caught exceptions are now collected and passed as the
InnerExceptionwhen throwing IDW10109:InnerExceptionis the original exception directlyInnerExceptionis anAggregateExceptioncontaining all originalsUpdated error text (
IDWebErrorMessage.cs)IDW10109 now mentions FIC/signed assertion scenarios and directs developers to check the inner exception for service-level error details such as AADSTS error codes.
Removed dead catch block (
TokenAcquisition.cs)Removed the inner
catch (ArgumentException ex) when (...)block that was unreachable dead code. The outercatch (Exception ex)at the method level already provides equivalent logging viaLogger.TokenAcquisitionError.Removed unused duplicate (
CertificateErrorMessage.cs)Removed
CertificateErrorMessage.ClientCertificatesHaveExpiredOrCannotBeLoaded, a duplicate IDW10109 definition with different wording that had zero references in source..gitignore: ignore MSBuild temp filesAdded
Temp/to.gitignore. The .NET 9+ SDK writes MSBuild temp files to aTemp/folder inside the repo root, which showed up as untracked files.Tests
Two new tests in
WithClientCredentialsTests.cs:AllCredentialsFail_SingleFailure_PreservesInnerExceptionAndErrorTextMsalServiceExceptionis set asInnerExceptionwith AADSTS error code accessible; error text includes FIC guidanceAllCredentialsFail_MultipleFailures_PreservesAllExceptionsViaAggregateExceptionAggregateExceptioninner containing all original exceptions