登入 iOS/macOS 的 MSAL

Microsoft 驗證資源庫(MSAL)應用程式會產生日誌訊息,有助於診斷問題。 應用程式只需幾行程式碼即可設定日誌,並自訂細節層級及是否記錄個人與組織資料。 我們建議您建立 MSAL 日誌實作,並提供使用者在有認證問題時提交日誌的方式。

記錄層級

MSAL 提供數個層級的記錄詳細程度:

  • LogAlways:此記錄層級不會進行任何層級篩選。 所有層級的日誌訊息都會被記錄。
  • 關鍵:描述無法復原的應用程式或系統當機,或需要立即處理的災難性故障的日誌。
  • 錯誤:表示發生了問題,並已產生錯誤。 用於除錯與問題識別。
  • 警告:不一定有錯誤或故障,但主要用於診斷和定位問題。
  • 資訊性:MSAL 會記錄用於資訊用途的事件,不一定用於除錯。
  • Verbose(預設):MSAL 記錄函式庫行為的完整細節。

Note

並非所有 MSAL SDK 的日誌層級都可用

個人與組織資料

預設情況下,MSAL 記錄器不會擷取任何高度敏感的個人或組織資料。 圖書館提供啟用個人及組織資料記錄的選項,前提是您願意這麼做。

以下章節將提供更多關於您應用程式中 MSAL 錯誤記錄的詳細資訊。

適用於 iOS 和 macOS 的 MSAL 記錄 - ObjC

設定回調來擷取 MSAL 日誌,並將其整合到你自己的應用程式日誌中。 回呼函式的簽名如下所示:

/*!
    The LogCallback block for the MSAL logger

    @param  level           The level of the log message
    @param  message         The message being logged
    @param  containsPII     If the message might contain Personally Identifiable Information (PII)
                            this will be true. Log messages possibly containing PII will not be
                            sent to the callback unless PIllLoggingEnabled is set to YES on the
                            logger.

 */
typedef void (^MSALLogCallback)(MSALLogLevel level, NSString *message, BOOL containsPII);

例如:

[MSALGlobalConfig.loggerConfig setLogCallback:^(MSALLogLevel level, NSString *message, BOOL containsPII)
    {
        if (!containsPII)
        {
#if DEBUG
            // IMPORTANT: MSAL logs may contain sensitive information. Never output MSAL logs with NSLog, or print, directly unless you're running your application in debug mode. If you're writing MSAL logs to file, you must store the file securely.
            NSLog(@"MSAL log: %@", message);
#endif
        }
    }];

個人資料

預設情況下,MSAL 不會擷取或記錄任何個人資料。 該函式庫允許應用程式開發者透過 MSALLogger 類別中的屬性來開啟此功能。 開啟 pii.Enabled後,應用程式負責安全處理高度敏感資料並遵守法規要求。

// By default, the `MSALLogger` doesn't capture any PII

// PII will be logged
MSALGlobalConfig.loggerConfig.piiEnabled = YES;

// PII will NOT be logged
MSALGlobalConfig.loggerConfig.piiEnabled = NO;

記錄層級

使用 iOS 和 macOS 使用 MSAL 登入時,要設定日誌等級,請使用以下其中一個值:

Level Description
MSALLogLevelNothing 關閉所有記錄
MSALLogLevelError 預設層級,僅在錯誤發生時列印資訊
MSALLogLevelWarning Warnings
MSALLogLevelInfo 圖書館入口點,包含參數與各種鑰匙圈操作
MSALLogLevelVerbose API 追蹤

例如:

MSALGlobalConfig.loggerConfig.logLevel = MSALLogLevelVerbose;

日誌訊息格式

MSAL 日誌訊息的訊息部分格式為 TID = <thread_id> MSAL <sdk_ver> <OS> <OS_ver> [timestamp - correlation_id] message

例如:

TID = 551563 MSAL 0.2.0 iOS Sim 12.0 [2018-09-24 00:36:38 - 36764181-EF53-4E4E-B3E5-16FE362CFC44] acquireToken returning with error: (MSALErrorDomain, -42400) User cancelled the authorization session.

提供相關 ID 和時間戳記有助於追蹤問題。 時間戳記與相關 ID 資訊可在日誌訊息中取得。 唯一可靠的取回方式是從 MSAL 日誌訊息中取得。

下一步

欲了解更多程式碼範例,請參閱 Microsoft 身分識別平台 程式碼範例。