The challenge
Authentication that works correctly in a normal browser can break when the same application also runs inside a mobile webview or desktop shell.
The system needed a modern identity flow across multiple execution environments while preserving secure redirects, token handling, session behavior and sign-out expectations.
Why cross-platform authentication is different
A browser, a Capacitor application and an Electron desktop client do not share exactly the same redirect model.
Differences can include:
- which redirect URIs are valid;
- how external or in-app browsers return to the application;
- whether an existing identity-provider session causes automatic sign-in;
- how local application state is restored after authentication;
- how logout affects the local application versus the identity-provider session;
- how SPA token redemption rules apply;
- how nonce/state validation behaves across redirects.
Engineering approach
The authentication work focused on separating shared OIDC logic from environment-specific handling.
That included:
- defining consistent application-side authentication state;
- aligning redirect URIs with the supported client type;
- handling OIDC state and nonce validation;
- resolving platform-specific token redemption behavior;
- controlling when external versus embedded browser flows were appropriate;
- addressing logout expectations across web, mobile and desktop;
- preserving a mixed-authentication path where required by the wider product.
Security and supportability
Identity code tends to become fragile when platform workarounds are scattered through unrelated components.
A key architectural goal was to isolate authentication concerns so that redirect handling, token state and environment-specific behavior could evolve without spreading identity logic across the application.
What this work demonstrates
This case study reflects practical experience with:
- enterprise OIDC adoption;
- Azure identity integration;
- authentication across browser, mobile and desktop;
- secure redirect configuration;
- troubleshooting state/nonce and token-flow issues;
- designing logout behavior around actual session boundaries.
Client-identifying details, tenant configuration and security-sensitive values have been intentionally omitted.