An API that connects multiple Microsoft services, enabling data access and automation across platforms
Graph API GenericProvider fails with more than one scope
Hello!
Our target is to build an application which adds calendar entries into the personal outlook calendar.
There is a PHP example out there which I've successfully tested. But this example is using "Device Code".
I have defined an application in Azure as Web-App and and set permissions for 'User.Read.All', 'User.ReadBasic.All' both as delegated permissions and app permissions.
Using the GenericProvider in PHP I'm getting an error AADSTS650053, if I'm using more than one scope. Here is the example implementation.
// $scopes = ['openid', 'User.Read' ]; fails with error AADSTS650053
// $scopes = [ 'User.Read.All', 'User.ReadBasic.All' ]; fails with error AADSTS650053
// $scopes = ['User.ReadBasic.All']; // works
$scopes = ['openid']; // works
$oauthClient = new GenericProvider([
'clientId' => $clientId,
'clientSecret' => $clientSecret,
'redirectUri' => $redirectUri,
'urlAuthorize' => "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/authorize",
'urlAccessToken' => "https://login.microsoftonline.com/$tenantId/oauth2/v2.0/token",
'urlResourceOwnerDetails' => '',
'scopes' => $scopes,
]);
...
header('Location: ' . $oauthClient->getAuthorizationUrl());
What is wrong here?
Why only one scope is working?
Second question: can I modify the scope after getting a valid access token?
Any hint is welcome! :-)