用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/tomevault-io/skills-registry --skill maui-authentication命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
| Use when this capability is needed.
> Use when this capability is needed.
Review architecture and API design for the vfs-s3 project. Use when the user mentions @architect, asks to review an issue's design, discuss module boundaries, API shape, or architectural decisions for vfs-s3. Also trigger when the user wants to create an ADR (Architecture Decision Record) or evaluate a technical approach for the project. Intended for dispatch from Codex automation or Claude routines; GitHub trigger phrase: @vfs-s3-bot please prepare design doc Use when this capability is needed.
基于 SOC 职业分类
正在显示 SKILL.md
| name | maui-authentication |
| description | > Use when this capability is needed. |
❌ Never embed client secrets, API keys, or signing keys in a mobile app binary. They can be extracted trivially via decompilation.
The correct pattern:
WebAuthenticator pointing to your server endpointWindows WebAuthenticator is currently broken. See dotnet/maui#2702. Use MSAL or a WinUI-specific workaround for Windows auth flows.
Apple only returns the user's name and email on the first sign-in. Cache them immediately — subsequent sign-ins won't include them.
Set to true on iOS 13+ to force a fresh login prompt. When false (default), the auth session shares cookies with Safari — the user may be auto-logged in, which can confuse logout/switch-account flows.
The most common auth failure is a URI scheme mismatch. The CallbackUrl in code must exactly match:
DataScheme + DataHost in the IntentFilterCFBundleURLSchemes in Info.plistProtocol Name in Package.appxmanifestCallbackUrlWebAuthenticatorCallbackActivity with correct IntentFilter<queries> for Custom Tabs in the manifestCFBundleURLTypes in Info.plistSecureStorage, cleared on logoutTaskCanceledException handled gracefully in UI| Criteria | WebAuthenticator | MSAL.NET |
|---|---|---|
| Identity provider | Any OAuth 2.0 / OIDC | Microsoft Entra ID |
| Broker support (SSO) | ❌ No | ✅ Microsoft Authenticator, Company Portal |
| Conditional Access / MFA | ❌ Manual | ✅ Built-in |
| Token cache & refresh | ❌ Manual (SecureStorage) | ✅ Automatic |
| Complexity | Simple | More setup |
| Use when | Google, Apple, generic OIDC | Entra ID / Azure AD, Microsoft Graph |
Forgetting AuthenticationContinuationHelper.SetAuthenticationContinuationEventArgs in MainActivity.OnActivityResult causes auth to hang silently after the browser returns.
Without Entitlements.plist containing keychain group com.microsoft.adalcache, token caching fails silently and users are prompted to sign in every time.
When AcquireTokenSilent throws MsalUiRequiredException, the cached token is expired and interaction is needed. Always fall back to AcquireTokenInteractive.
// ❌ Ignoring MsalUiRequiredException — user gets a crash
var result = await _pca.AcquireTokenSilent(scopes, account).ExecuteAsync(ct);
// ✅ Fall back to interactive when silent fails
try
{
result = await _pca.AcquireTokenSilent(scopes, account).ExecuteAsync(ct);
}
catch (MsalUiRequiredException)
{
result = await _pca.AcquireTokenInteractive(scopes).ExecuteAsync(ct);
}
// ✅ Don't treat cancellation as an error
catch (MsalClientException ex) when (ex.ErrorCode == "authentication_canceled")
{
return null; // User cancelled — not an error
}
In MAUI Blazor Hybrid apps, authentication must happen at the MAUI layer (MSAL.NET), not in the Blazor WebView. Don't use AddMicrosoftIdentityWebApp or server-side OIDC patterns. Instead:
IAuthService (MSAL.NET)MsalAuthenticationStateProvider exposes auth state to BlazorHttpClient with DelegatingHandler attaches bearer tokens automaticallyMicrosoft.Identity.Client NuGet package addedAuthConfig / appsettings.json has ClientId, TenantId, ScopesAndroidManifest.xml has <queries> for broker and browsersMainActivity.OnActivityResult calls AuthenticationContinuationHelperInfo.plist has CFBundleURLSchemes with msauth.{BundleId}Entitlements.plist has keychain group com.microsoft.adalcacheAppDelegate.OpenUrl calls AuthenticationContinuationHelperIAuthService registered as singleton in DIDelegatingHandler attached to HttpClient for API callsMsalUiRequiredException handled (triggers interactive sign-in)MsalClientException with authentication_canceled handled gracefullyConverted and distributed by TomeVault — claim your Tome and manage your conversions.