使用Java调用MS Graph的getAllSites()时遇AccessDenied错误求助
Java调用MS Graph getAllSites()时AccessDenied错误解决方案
问题概述
使用Java调用MS Graph的getAllSites()方法时触发权限拒绝错误,代码取自Microsoft Learn,目标是获取所有SharePoint站点并下载其中一个站点的文件。
代码示例
final UsernamePasswordCredential credential = new UsernamePasswordCredentialBuilder() .clientId(clientId).tenantId(tenantId).username(userName).password(password) .build(); final GraphServiceClient graphClient = new GraphServiceClient(credential, scopes); GetAllSitesGetResponse getAllSitesGetResponse = graphClient.sites().getAllSites().get(); List<Site> value = getAllSitesGetResponse.getValue();
错误信息
Exception in thread "main" com.microsoft.graph.models.odataerrors.ODataError: Access denied at com.microsoft.graph.models.odataerrors.ODataError.createFromDiscriminatorValue(ODataError.java:36) at com.microsoft.kiota.serialization.JsonParseNode.getObjectValue(JsonParseNode.java:212) at com.microsoft.kiota.http.OkHttpRequestAdapter.lambda$throwIfFailedResponse$0(OkHttpRequestAdapter.java:674) at com.microsoft.kiota.ApiExceptionBuilder.<init>(ApiExceptionBuilder.java:26) at com.microsoft.kiota.http.OkHttpRequestAdapter.throwIfFailedResponse(OkHttpRequestAdapter.java:673) at com.microsoft.kiota.http.OkHttpRequestAdapter.send(OkHttpRequestAdapter.java:281) at com.microsoft.graph.sites.getallsites.GetAllSitesRequestBuilder.get(GetAllSitesRequestBuilder.java:60) at com.microsoft.graph.sites.getallsites.GetAllSitesRequestBuilder.get(GetAllSitesRequestBuilder.java:46)
当前依赖版本
<dependency> <groupId>com.microsoft.graph</groupId> <artifactId>microsoft-graph</artifactId> <version>6.13.0</version> </dependency> <dependency> <groupId>com.microsoft.graph</groupId> <artifactId>microsoft-graph-core</artifactId> <version>3.1.14</version> </dependency>
解决方案
1. 确认权限配置
- 权限类型与范围:
getAllSites接口需要以下权限之一:- 委托权限:
Sites.Read.All或Sites.ReadWrite.All(需用户或管理员同意) - 应用权限:
Sites.Read.All(需管理员同意)
- 委托权限:
- 权限授予状态:在Azure AD应用注册中,确保已为应用授予对应权限并完成管理员同意(应用权限或需要管理员同意的委托权限必须由管理员批准)。
- Scopes参数验证:如果使用委托流(如当前的UsernamePasswordCredential),scopes需包含
"https://graph.microsoft.com/Sites.Read.All";如果使用应用流,scopes应为["https://graph.microsoft.com/.default"]。
2. 调整认证方式
当前使用的UsernamePasswordCredential(ROPC流)存在限制:不支持MFA,部分租户可能禁用该流,且不推荐用于生产环境。如果是服务端应用,建议改用客户端凭据流,搭配应用权限:
final ClientSecretCredential credential = new ClientSecretCredentialBuilder() .clientId(clientId) .tenantId(tenantId) .clientSecret(clientSecret) .build(); final GraphServiceClient graphClient = new GraphServiceClient(credential, Collections.singletonList("https://graph.microsoft.com/.default")); GetAllSitesGetResponse getAllSitesGetResponse = graphClient.sites().getAllSites().get(); List<Site> value = getAllSitesGetResponse.getValue();
3. 验证用户/应用权限
使用Graph Explorer测试:用相同的用户账号调用GET /sites/getAllSites,确认用户本身是否具备访问所有站点的权限;若使用应用权限,需确认应用已被授予对应权限。
4. 站点文件下载示例
获取站点后,可通过以下代码下载指定文件(需替换占位符为实际ID):
// 下载站点中指定文件 InputStream fileStream = graphClient.sites("{site-id}") .drives("{drive-id}") .items("{item-id}") .content() .get(); // 将文件流写入本地 Files.copy(fileStream, Paths.get("local-file-path"), StandardCopyOption.REPLACE_EXISTING);
内容的提问来源于stack exchange,提问作者Daemon_Demon
相关产品推荐
相关产品推荐

