Skip to content

[Bug] Plaintext Storage of Authentication & Identification Tokens #5450

@JoacimWall

Description

@JoacimWall

Library version used

4.76.0

.NET version

Dotnet 9.0.202

Scenario

PublicClient - mobile app

Is this a new or an existing app?

The app is in production, and I have upgraded to a new version of MSAL

Issue description and reproduction steps

Hi
We have got a security check of the app from external company and get this report back.

Image

Relevant code snippets

Expected behavior

No response

Identity provider

Microsoft Entra ID (Work and School accounts and Personal Microsoft accounts)

Regression

No response

Solution and workarounds

No response

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions