从ASP.NET Core 8 MVC打开SharePoint链接时出现cdn.office.net错误
内网ASP.NET Core 8 MVC视图中有以下链接代码:
<a href="https://mysharepointsite.sharepoint.com">SharePoint Link</a>
点击该链接时,触发来自cdn.office.net下shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js的JavaScript错误,错误堆栈如下:
Message=
Source=
StackTrace:
at t [as constructor] (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:29:8969)
at new t (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:29:19920)
at t.createRefreshRequiredError (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:29:23222)
at t. (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:74:24113)
at https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:24:1785
at Object.next (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:24:1890)
at https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:24:827
at new Promise ()
at C (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:24:572)
at t.acquireCachedToken (https://res-1.cdn.office.net/shellux/suiteux.shell.msaltokenfactoryiframe.f8596e6e29fad0034808.js:74:23297)
这个错误是Office 365的Shell UX脚本在尝试获取缓存的身份验证令牌时失败,触发了令牌刷新要求的错误。核心问题是当前内网ASP.NET Core站点的身份上下文,和SharePoint站点的Azure AD身份上下文不兼容:
- 点击链接在当前窗口打开SharePoint时,Office全局Shell脚本会尝试复用当前页面的身份会话,但内网站点的身份环境和SharePoint的身份系统不匹配,导致令牌获取逻辑抛出异常。
- 堆栈里的
createRefreshRequiredError直接指向令牌刷新流程失败,说明现有会话无法被SharePoint的身份验证系统识别或复用。
有三种可行的解决方式:
方式1:在新窗口打开链接(推荐)
修改链接添加target="_blank"属性,让SharePoint在独立窗口加载,彻底避免和当前内网站点的身份上下文冲突:
<a href="https://mysharepointsite.sharepoint.com" target="_blank" rel="noopener noreferrer">SharePoint Link</a>
额外添加rel="noopener noreferrer"是为了安全,防止新窗口对原页面的潜在控制。
方式2:禁用Office Shell脚本自动注入
如果必须在当前窗口打开,可以通过元标签阻止Office的Shell脚本注入到页面中:
在MVC视图的<head>区域添加:
<meta name="Office.AutoShellInject" content="false" />
这个标签会告诉Office CDN不要自动加载Shell UX相关脚本,从根源上避免触发令牌验证逻辑。
方式3:统一身份上下文(复杂场景)
如果内网站点和SharePoint属于同一Azure AD租户,可以配置ASP.NET Core站点使用Azure AD身份验证,让两个站点共享有效身份会话,这样Office脚本就能正常获取令牌。但这种方式需要调整站点的身份验证配置,适合有统一身份管理需求的场景。
内容的提问来源于stack exchange,提问作者mjh737

