We have a Xamarin Forms code base that has been using MSAL since 1.1.4 in 2019, we are now using 4.22.0.
The app has always kept it's own copy of the accesstoken acquired either silectly or interactively and it is the app's copy that it uses when accessing various B2C secured apis.
It only calls AcquireTokenSilent or AcquireTokenInteractive on initial logon or when a 401 is detected.
We beleive we have an issue with the storing of token and from what I understand MSAl caches the access token itself anyway. Looking at the documentation and samples we should be calling AcquireTokenSilent whenever we need the token and handling MSALUIRequiredException to call AcquireTokenInteractive.
Is this correct, does MSAL cache the accesstoken?
When we build the PublicClientApplication we do not call currently call WithIosKeychainSecurityGroup. Is that a prerequisite for the cachhing of tokens to work on iOS?
PublicClientApplicationBuilder
.Create(ClinicalServicesSettings.ClientID)
.WithB2CAuthority(ClinicalServicesSettings.Authority)
.Build()