You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Azure API Manager中基于Audience ID条件限制API端点访问?

Azure APIM 多Audience权限控制策略实现方案

直接上可行的策略配置,核心是在inbound阶段用<choose>结合上下文变量做精准的权限判断:

前置条件

先确保你已经在API级别或产品级别配置了JWT验证策略,把Token里的aud声明解析到APIM的用户上下文里,比如:

<validate-jwt header-name="Authorization" failed-validation-httpcode="401" failed-validation-error-message="Invalid token">
    <openid-config url="https://your-identity-provider/.well-known/openid-configuration" />
    <required-claims>
        <claim name="aud" match="Any">
            <value>full-access-aud-id</value>
            <value>restricted-access-aud-id</value>
        </claim>
    </required-claims>
</validate-jwt>

这一步先过滤掉不在允许列表里的Audience,避免后续无效判断。

核心权限控制策略

在上述JWT验证之后,添加以下<choose>策略,实现细粒度的端点访问控制:

<choose>
    <!-- 全权限Audience,允许访问所有端点 -->
    <when condition="@(context.User.Claims.GetValueOrDefault("aud") == "full-access-aud-id")">
        <return-response>
            <!-- 留空直接放行,可按需添加日志等逻辑 -->
        </return-response>
    </when>
    <!-- 受限Audience,仅允许访问指定2个端点 -->
    <when condition="@(context.User.Claims.GetValueOrDefault("aud") == "restricted-access-aud-id")">
        <choose>
            <!-- 替换为你实际允许的端点路径 -->
            <when condition="@(context.Request.Path.StartsWithSegments("/api/v1/allowed-endpoint-1") || context.Request.Path.StartsWithSegments("/api/v1/allowed-endpoint-2"))">
                <return-response>
                    <!-- 放行,无操作 -->
                </return-response>
            </when>
            <!-- 其他端点直接拒绝 -->
            <otherwise>
                <return-response>
                    <set-status code="403" reason="Forbidden" />
                    <set-body>{"message": "You are not allowed to access this endpoint"}</set-body>
                </return-response>
            </otherwise>
        </choose>
    </when>
    <!-- 未匹配的Audience,直接拒绝 -->
    <otherwise>
        <return-response>
            <set-status code="403" reason="Forbidden" />
            <set-body>{"message": "Invalid audience"}</set-body>
        </return-response>
    </otherwise>
</choose>

关键逻辑说明

  • 用context.User.Claims.GetValueOrDefault("aud")直接获取Token中的Audience ID,这是APIM解析JWT后自动存入上下文的变量,无需手动解析Token。
  • <choose>策略支持嵌套,完美实现「aud等于指定值 且 路径匹配」的逻辑与判断,比required-claims的单一匹配更灵活。
  • 权限判断放在inbound阶段,可尽早拦截非法请求,避免不必要的后端转发。

你之前踩坑的原因

  1. required-claims的Match="Any"是满足任一条件即通过,无法实现「同时满足aud和路径」的逻辑与需求。
  2. 放在outbound阶段处理太晚,请求已经到达后端并返回响应,失去了拦截的意义——其实outbound阶段同样可以通过context.User.Claims获取Audience,只是时机不对。

内容的提问来源于stack exchange,提问作者Stephen Rushton

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 11:07:34