Collect Auth Flow Questions

<< Click to Display Table of Contents >>

Navigation:  Collect > Collect Mobile > Mobile Troubleshooting >

Collect Auth Flow Questions

Q: What is the normal workflow for tokens and EQuIS Collect Mobile?

A: Entra ID/AAD user workflow – The user presses the “Sign in with Microsoft” button > browser opens > successful authentication > Collect navigates to the initial landing page (templates/forms page).

•The entire process of obtaining this token is handled by the Microsoft.Identity.Client library’s interface called IPublicClientApplication.

•Once a successful login is achieved, there are two tokens – access and identity – obtained from the service which was used for authentication (Microsoft Entra ID, OpenID, etc.). These tokens are used in the default headers to make API calls to Collect Enterprise endpoints. There is no expiration on these tokens within the application; that is not to say they do not expire, rather they are used in Collect until an unsuccessful API call is made, the user logs out and logs back in, or the user goes from offline to online. At which point the tokens are ‘refreshed’ utilizing either interactive or silent authentication, the former is where the pop-up opens and the latter is done behind the scenes. The method of authentication, silent or interactive, depends on the login method that was used, if a user logged in with a PIN and is going to online from offline, the authentication will be interactive otherwise it will be silent.      

 

Q: Is a token generated when a user logs in?

A: Yes – see description above.

 

Q: What is the refresh mechanism on the tokens?

A: An attempt is made to refresh a token when an API call to a Collect Enterprise endpoint fails and the user did not use basic login to log into Collect or when the user goes from offline to online.

•Do the tokens auto-refresh every X amount of minutes?

oNo.

•Does a user need to do something to refresh?

oIf a user is experiencing issues, it is recommend to attempt to go from online to offline then back online. This will trigger the refresh token event.

 

Q: If expiration has passed, how does Collect Mobile get another token so the new token/session is not expired?

A: See previous answers describing silent/interactive authentication. Additionally, there could be a situation where silent authentication does not work as expected to refresh the token. If a user did not login with their PIN, and possibly the cookies or cache are cleared in their system's default browser, then the stored profile used for silent authentication would not be present. Therefore, the current token would likely be made null, and the user would need to log out and log back in so they can obtain a new set of tokens.    

 

Q: What factors attribute to when a token expire?

A: A token default will last 90 days. This could be changed on the client's deployed EQuIS Enterprise site, depending on the way in which their server is configured. For more information, see Refresh tokens in the Microsoft identity platform.

 

Q: How can a Collect Mobile user generate new tokens if there are errors in the log regarding expired or invalid tokens?

A: See previous answers; in short, logging out and logging back in or attempting to go from online to offline and back online could work.

 

Q: How does refreshing a token and loss of network connectivity work?

A: Token refresh requires network connectivity and cannot occur while the device is offline. Collect stores the most recent authentication tokens in the local database and in application memory. Once connectivity is restored and the user reconnects, Collect attempts to re-authenticate automatically using silent authentication. If silent authentication is not possible, such as when the user signed in with a PIN, interactive authentication may be required.