调用Microsoft Graph获取SharePoint站点最近文件遇accessDenied错误
环境信息
OAuth权限范围
使用的权限范围如下:
offline_access openid profile email Mail.Send User.Read Files.ReadWrite.All Sites.ReadWrite.All
权限已覆盖所需范围。
成功的API调用
- 获取站点驱动器信息
调用GET请求https://graph.microsoft.com/v1.0/sites/:siteId/drive,返回结果正常:
{ '@odata.context': 'https://graph.microsoft.com/v1.0/$metadata#drives/$entity', createdDateTime: '2023-05-20T23:20:12Z', description: '', id: 'b!ZVW3mC07Ck2fnj47xT3h02LQsvIyQjrqceQpFvTR0S1e1IUAqav15AMInFCkSIsA', lastModifiedDateTime: '2024-05-16T16:11:31Z', name: 'Documents', webUrl: 'https://xample.sharepoint.com/sites/SomedaySite/Shared%20Documents', driveType: 'documentLibrary', createdBy: { user: { displayName: 'System Account' } }, lastModifiedBy: { user: { email: 'e5admin@xample.onmicrosoft.com', id: '596a9690-ab24-4dbc-b8ef-5e626fa001e2', displayName: 'Jane Doe' } }, owner: { group: { email: 'SomedaySite@xample.onmicrosoft.com', id: '8e46abd5-fd42-4b0b-b6ef-59cb232053fe', displayName: 'Someday Site Owners' } }, quota: { deleted: 0, remaining: 27487788554469, state: 'normal', total: 27487790694400, used: 2139931 } }
- 获取驱动器根目录信息
调用GET请求https://graph.microsoft.com/v1.0/sites/:siteId/drive/root,返回结果正常:
{ '@odata.context': 'https://graph.microsoft.com/v1.0/$metadata#Collection(driveItem)/$entity', '@microsoft.graph.Decorator': 'decorator has been deprecated. Refer to folder.decorator', createdDateTime: '2023-05-20T23:20:12Z', id: '01WGOKW5F6Y2GOVW7725BZO354PWSELRRZ', lastModifiedDateTime: '2024-05-20T20:27:41Z', name: 'root', parentReference: { driveType: 'documentLibrary', driveId: 'b!ZVW3mC07Ck2fnj47xT3UAqav15AMInFCkSIsAh02LQsvIyQjrqceQpFvTR0S1e1I' }, webUrl: 'https://xample.sharepoint.com/sites/SomedaySite/Shared%20Documents', fileSystemInfo: { createdDateTime: '2023-05-20T23:20:12Z', lastModifiedDateTime: '2024-05-20T20:27:41Z' }, folder: { childCount: 3 }, root: {}, size: 81011 }
失败的API调用
调用GET请求 https://graph.microsoft.com/v1.0/sites/:siteId/drive/recent 时返回权限错误:
{ error: { code: 'accessDenied', message: 'The current caller is not the drive owner.', innerError: { date: '2024-05-27T17:00:53', 'request-id': '09988d39-2ecc-46d0-ba52-dd0187070c8e', 'client-request-id': '09988d39-2ecc-46d0-ba52-dd0187070c8e' } } }
问题
- 为何前两个调用正常,第三个调用失败?
- 如何获取SharePoint站点的最近文件及文件夹列表?
解答
1. 调用失败原因
/drive/recent 端点的设计逻辑是返回当前用户个人最近访问/修改的文件,但你访问的驱动器属于SharePoint站点组(Someday Site Owners),而非当前用户个人所有。该端点的权限校验逻辑特殊,会检查调用者是否是驱动器的直接所有者(个人驱动器所有者是用户,站点库所有者是组),因此即使你拥有站点库的读写权限,也会触发accessDenied错误。
前两个端点/drive和/drive/root是查询站点库的基础信息,权限校验仅验证是否拥有站点库的访问权限,所以能正常返回结果。
2. 获取站点最近文件的替代方案
放弃使用/drive/recent,改用以下两种方式:
- 方式一:查询站点库内最近修改的项
通过排序获取最近修改的内容,支持直接查询根目录或递归搜索所有子文件夹:
// 查询根目录下最近修改的20条内容 GET https://graph.microsoft.com/v1.0/sites/:siteId/drive/root/children?orderBy=lastModifiedDateTime desc&top=20 // 递归搜索站点库内所有最近修改的20条内容 GET https://graph.microsoft.com/v1.0/sites/:siteId/drive/root/search(q='')?orderBy=lastModifiedDateTime desc&top=20
- 方式二:使用站点搜索接口查询
通过站点搜索端点,过滤指定时间范围内修改的内容:
GET https://graph.microsoft.com/v1.0/sites/:siteId/search(q='')?$filter=lastModifiedDateTime ge 2024-05-20T00:00:00Z&orderBy=lastModifiedDateTime desc&top=20
以上两种方式均可基于你现有的Files.ReadWrite.All/Sites.ReadWrite.All权限,正常获取站点内的最近文件和文件夹。
内容的提问来源于stack exchange,提问作者dvdsmpsn
相关产品推荐
相关产品推荐

