You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot+Spring Security+Azure B2C获取AccessToken部分字段为Null的原因

问题:Azure B2C Client Credentials模式获取令牌时多字段返回Null的原因?

我使用Spring Boot结合Spring Security与Microsoft Azure B2C,通过以下代码获取AccessToken:

GetTokenRequestPayload req = new GetTokenRequestPayload(GRANT_TYPE_CREDENTIAL,certSecretValue, clientId, graphAPI ? configuration.getMsGraphScope() : configuration.getAppScope());
RestTemplate restTemplate = new RestTemplate();

HttpHeaders headers = new HttpHeaders();
headers.setContentType(MediaType.APPLICATION_FORM_URLENCODED);

// Construction du body de la requete
MultiValueMap<String, String> map = new LinkedMultiValueMap<>();
map.add("grant_type",req.getGrant_type());
map.add("client_secret",req.getClient_secret());
map.add("client_id",req.getClient_id());
map.add("scope",req.getScope());
HttpEntity<MultiValueMap<String, String>> entity = new HttpEntity<>(map, headers);

ResponseEntity<TokenResponse> response = restTemplate.exchange(configuration.getAccessGraphTokenUri(), HttpMethod.POST, entity, TokenResponse.class);

请求URL为:https://login.microsoftonline.com/04a485d4-754c-4912-b891-..../oauth2/v2.0/token,授权类型为client_credentials。返回结果中多个字段为Null,但AccessToken中的时间字段(iat、nbf、exp)正常。请问为何Azure会返回多个Null字段?


原因分析

  • client_credentials模式的特性决定:这个模式是以应用身份直接获取令牌,全程没有用户参与,所以Azure不会返回任何和用户身份相关的字段(比如id_token、refresh_token、用户信息类字段)。如果你的TokenResponse实体类定义了这些字段,自然会被序列化为Null。
  • 实体类与响应结构不匹配:Azure在client_credentials模式下的标准响应字段只有access_token、token_type、expires_in、ext_expires_in这几个。如果你的TokenResponse额外定义了不属于该模式的字段,这些字段必然是Null。
  • 令牌声明与响应字段的区别:你提到的iat、nbf、exp是嵌入在access_token这个JWT令牌内部的标准声明,并非响应体的顶级字段,所以解析令牌时能拿到这些值,但响应体里不会单独返回它们,这属于正常现象。

内容的提问来源于stack exchange,提问作者robert trudel

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 14:50:55