使用RestAPI对接Azure Bot Service时的权限配置问题排查
Flask后端对接Azure Bot Service回复401权限问题
问题背景
本地运行Flask后端服务,通过ngrok暴露给Azure,与Azure Bot Service对接。后端可接收「Test in Web Chat」的消息,但回复时返回401错误,推测需为API配置正确权限,机器人为单租户类型。
生成响应令牌的代码
url = "https://login.microsoftonline.com/botframework.com/oauth2/v2.0/token" headers = { "Content-Type": "application/x-www-form-urlencoded" } data = { "grant_type": "client_credentials", "client_id": client_id, "client_secret": client_secret, "scope": "https://api.botframework.com/.default" }
解码后的令牌
{ "typ": "JWT", "alg": "RS256", "x5t": "imi0Y2z0dYKxBttAqK_Tt5hYBTk", "kid": "imi0Y2z0dYKxBttAqK_Tt5hYBTk" }.{ "aud": "https://api.botframework.com", "iss": "https://sts.windows.net/d6d49420-f39b-4df7-a1dc-d59a935871db/", "iat": 1740236233, "nbf": 1740236233, "exp": 1740322933, "aio": "k2RgYGC/rfLecEbpExbj5edObn+xAAA=", "appid": "59db3818-3845-4cd7-93ef-0ec3efff7974", "appidacr": "1", "idp": "https://sts.windows.net/d6d49420-f39b-4df7-a1dc-d59a935871db/", "idtyp": "app", "rh": "1.AW4AIJTU1pvz902h3NWak1hx20IzLY0pz1lJlXcODq-9FrxeAQBuAA.", "tid": "d6d49420-f39b-4df7-a1dc-d59a935871db", "uti": "-m34WPWqiUSVGPdqi39PAA", "ver": "1.0", "xms_idrel": "13 32" }.[Signature]
回复Azure Bot的代码
url = f"https://smba.trafficmanager.net/emea/v3/conversations/{conversation_id}/activities" headers = { "Authorization": f"Bearer {token}", "Content-Type": "application/json" } json_block= { "type": "message", "text": "Hello from the bot!" } try: response = requests.post(url, headers=headers, json=json_block)
错误信息
{"message":"Authorization has been denied for this request."}
已配置的Microsoft Graph API权限
| Permission | 类型 | 描述 |
|---|---|---|
| APIConnectors.Read.All | 委派权限 | 读取身份验证流的API连接器 |
| APIConnectors.ReadWrite.All | 委派权限 | 读取和写入身份验证流的API连接器 |
| ChannelMessage.Read.All | 应用权限 | 读取所有频道消息 |
| Chat.Create | 委派权限 | 创建聊天 |
| Chat.ManageDeletion.All | 委派权限 | 删除和恢复已删除的聊天 |
| Chat.Read | 委派权限 | 读取用户聊天消息 |
| Chat.ReadBasic | 委派权限 | 读取用户聊天线程的名称和成员 |
| Chat.ReadWrite | 委派权限 | 读取和写入用户聊天消息 |
| Chat.ReadWrite.All | 委派权限 | 读取和写入所有聊天消息 |
| Chat.ReadWrite.All | 应用权限 | 读取和写入所有聊天消息 |
| ChatMessage.Read | 委派权限 | 读取用户聊天消息 |
| ChatMessage.Send | 委派权限 | 发送用户聊天消息 |
| User.Read.All | 应用权限 | 读取所有用户的完整个人资料 |
后续考虑
目前已有使用Python Bot Service SDK的类似问题案例,若RestAPI方式无法推进,将考虑切换至该SDK。
内容的提问来源于stack exchange,提问作者OrigamiEye
相关产品推荐
相关产品推荐

