I'm building a .NET core Web API that’s secured using AAD and which uses ADAL to call a downstream API using the on-behalf-of flow…. similar to this Azure Sample:
https://github.com/Azure-Samples/active-directory-dotnet-webapi-onbehalfof
What are the best practices for the token cache that should be used in a scenario like this?
Is the default cache acceptable?
Should you ever not have a cache?
AuthenticationContext authContext = new AuthenticationContext(authority, null)
If you should build your own then is there a good reference implementation to use?