You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

调用Microsoft Fabric Git Update API时认证失败求助

问题:Azure DevOps管道调用Microsoft Fabric Git Update API返回未授权错误

我在Azure DevOps发布管道中配置了两个阶段的PowerShell脚本,分别用于生成Access Token和调用Microsoft Fabric的Git Update API。使用的是已分配工作区管理员权限的Entra ID服务主体,但调用API时返回未授权错误。

认证脚本

# Define Variables
$tokenUrl = "https://login.microsoftonline.com/**/oauth2/v2.0/token"
$scope= "https://api.fabric.microsoft.com/.default"

# Prompt for user credentials 
$authParams = @{
    "client_id"    = $env:clientId
    "scope"        = $scope
    "grant_type"   = "client_credentials"
    "client_secret"     = $env:client_secret
}

# Get Access Token
$response = Invoke-RestMethod -Method Post -Uri $tokenUrl -ContentType "application/x-www-form-urlencoded" -Body $authParams

# Extract and Output the Token
$accessToken = $response.access_token
Write-Output "Full Response: $($response | ConvertTo-Json -Depth 10)"

# Ensure access token is retrieved
if (-not $response.access_token) {
    Write-Error "Access token is empty."
    exit 1
}

# Store Access Token as a Pipeline Variable (for next task)
Write-Output "##vso[task.setvariable variable=accessToken;isSecret=true]$accessToken"

Write-Output "Stored Access Token Length: $($accessToken.Length)"

主API调用脚本

# Retrieve the Access Token from Azure DevOps Pipeline Variable
$accessToken = "$(accessToken)"  # Ensure this is set in the pipeline

Write-Output "Access token Length: $($accessToken.Length)"

# Ensure the token is not empty
if (-not $accessToken) {
    Write-Error "Access token is empty. Ensure it is being passed correctly from the authentication task."
    exit 1
}

# Set headers for API request
$headers = @{
    "Authorization" = "Bearer $accessToken"
    "Content-Type"  = "application/json"
}

# Define API URL 

$workspaceId = "**"
$apiUrl = "https://api.fabric.microsoft.com/v1/workspaces/$workspaceId/git/updateFromGit"

# Retrieve the latest commit hash from GitHub via Azure DevOps Pipeline variable
$commitId = "$(Build.SourceVersion)"  # Ensure this is available in the pipeline

# Ensure commitId is not empty
if (-not $commitId) {
    Write-Error "Commit ID is empty. Ensure the pipeline is triggered from a Git commit."
    exit 1
}

# Define request body
$body = @{
    "remoteCommitHash" = "**"
} | ConvertTo-Json -Depth 10

# Call Microsoft Fabric API
try {
    $response = Invoke-RestMethod -Uri $apiUrl -Method Post -Headers $headers -Body $body -UseBasicParsing
    Write-Output "Fabric API Response: $response"
} catch {
    Write-Error "Error calling Fabric API: $_"
    exit 1
}

错误信息

Access token Length: 1292 2025-03-06T07:43:51.9969024Z
D:\a_temp\7**6.ps1 : Error calling Fabric API:
2025-03-06T07:43:51.9969588Z
{"requestId":"2dc3605d-9891-4f60-b54d-72ba4da52809","errorCode":"Unauthorized","message":"The caller is not authenticated to access this resource"} 2025-03-06T07:43:51.9970968Z At line:1 char:1

排查与解决步骤

1. 验证令牌有效性与权限范围

  • 用jwt.ms解码获取的Access Token,确认:
    • aud(受众)为https://api.fabric.microsoft.com
    • roles字段包含Workspace.ReadWrite.All或目标工作区的管理员级权限
  • 检查认证scope是否为https://api.fabric.microsoft.com/.default,无拼写错误

2. 确认服务主体的权限配置

  • 服务主体必须直接添加为目标Fabric工作区的管理员,而非仅依赖Entra ID角色分配
  • 在Fabric门户进入目标工作区→工作区设置→成员,确认服务主体存在且角色为管理员
  • 若使用Entra ID角色(如Fabric管理员),需等待15-30分钟确保权限生效

3. 检查管道变量传递

  • 认证脚本中##vso[task.setvariable]命令无多余空格,变量名accessToken拼写一致
  • API调用脚本中改用$env:accessToken获取变量,避免字符串插值可能的篡改
  • 测试时可临时移除isSecret=true,打印令牌前几位确认传递正确(测试后恢复保密)

4. 验证API请求参数

  • 确认workspaceId和remoteCommitHash无拼写错误,提交哈希需存在于Fabric关联的Git仓库
  • 检查Authorization头格式:Bearer与令牌之间必须有一个空格,无多余字符

5. 排查区域与仓库关联问题

  • 若工作区不在公共区域,需使用对应区域的API URL(如中国区用https://api.fabric.microsoft.com.cn)
  • 确认Fabric工作区已正确关联目标Git仓库,服务主体对该仓库有读取权限

内容的提问来源于stack exchange,提问作者Salman

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 23:47:02