使用httr2实现Azure AD多范围设备码OAuth认证的问题求助
问题:用httr2实现Azure AD设备码OAuth流的多范围令牌获取与缓存
我们正尝试重构原使用AzureAuth的代码,改用httr2实现Azure Active Directory的设备码OAuth流认证。核心需求是:获取多个范围的访问令牌,但用户仅需完成一次认证,同时要对令牌进行缓存。
AzureAuth通过利用一个范围的刷新令牌来获取另一个范围的访问令牌实现该功能,我们尝试用httr2::oauth_flow_refresh()复现此逻辑,脱敏代码如下:
scope_client <- paste0("XYZ", "/.default offline_access") scope <- "https://graph.microsoft.com/.default offline_access" oauth_client <- httr2::oauth_client( id = "XYZ", token_url = "https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token" ) token_app <- httr2::oauth_token_cached( client = oauth_client, flow = httr2::oauth_flow_device, flow_params = list( auth_url = "https://login.microsoftonline.com/{tenant}/oauth2/v2.0/devicecode", scope = scope_client ), cache_disk = TRUE, cache_key = rlang::hash(scope_client) ) token <- httr2::oauth_token_cached( client = oauth_client, flow = httr2::oauth_flow_refresh, flow_params = list( refresh_token = token_app$refresh_token, scope = scope ), cache_disk = TRUE, cache_key = rlang::hash(scope) )
但运行时收到httr2::oauth_flow_refresh()的警告,原因是服务器返回了新的刷新令牌。此外,该函数文档显示其主要用于测试,因此我们认为应有更优方案。我们更倾向于使用req_oauth_*()系列函数直接授权请求,由httr2管理令牌,但无法实现该方案,特此求助。
内容的提问来源于stack exchange,提问作者janni
相关产品推荐
相关产品推荐

