You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft Drive认证成功后无法获取驱动器项问题求助

问题排查:Microsoft Drive API返回空目录但实际存在内容

问题概述

我正在开发Web应用,首次尝试用Node.js + Passport集成Microsoft Drive。已通过以下代码完成认证流程,成功获取accessToken和refreshToken,但调用API列出根目录文件时返回空数组,实际根目录存在多个文件夹和文件。

认证代码

const MicrosoftStrategy = require('passport-microsoft').Strategy;

passport.use(
    new MicrosoftStrategy(
        {
            authorizationURL: `${process.env.MICROSOFT_URL}/authorize`,
            callbackURL: `${process.env.CALLBACK_URL}/oauth/microsoft/callback`,
            clientID: process.env.MICROSOFT_CLIENT_ID,
            clientSecret: process.env.MICROSOFT_CLIENT_SECRET,
            tokenURL: `${process.env.MICROSOFT_URL}/token`
        },
        (accessToken, refreshToken, profile, cb) => {
            profile.tokens = { microsoft: { accessToken, refreshToken } };
            cb(null, profile);
        }
    )
);

router.get(
    '/auth/microsoft',
    passport.authenticate('microsoft', { scope: ['user.read', 'offline_access', 'Files.Read.All', 'Files.Read', 'Files.ReadWrite.All', 'Sites.Read.All', 'Sites.ReadWrite.All', 'consent'] })
);

测试请求与响应

调用的cURL命令:

curl -X GET \
     -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \
     -H "Content-Type: application/json" \
     "https://graph.microsoft.com/v1.0/me/drive/root/children"

返回结果:

{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#Collection(driveItem)","value":[]}

排查步骤

1. 确认访问的Drive是否正确

/me/drive默认指向个人OneDrive,如果你的文件存储在OneDrive for Business或SharePoint站点,需要切换对应端点:

  • OneDrive for Business:https://graph.microsoft.com/v1.0/users/{user-id}/drive/root/children
  • SharePoint站点文档库:https://graph.microsoft.com/v1.0/sites/{site-id}/drive/root/children

先调用https://graph.microsoft.com/v1.0/me/drive查看当前Drive的基本信息,确认是否为目标存储位置。

2. 验证Token权限范围

用jwt.io解析你的accessToken,查看scp字段,确认包含Files.Read.All或Files.Read权限:

  • 如果token中没有对应权限,可能是用户授权时未同意,或应用注册时权限配置有误(比如设置了需管理员审批的权限但未获得同意)。

3. 检查根目录实际状态

调用https://graph.microsoft.com/v1.0/me/drive/root获取根目录详情,查看folder.childCount字段是否大于0,确认API能识别到根目录的内容数量。

4. 检查应用注册配置

在Azure AD应用注册后台:

  • 确认重定向URI与代码中callbackURL完全一致;
  • 确认Files.Read.All等权限为委托权限(Delegated permissions),且已完成授权(个人账户自动同意,组织账户可能需管理员审批)。

5. 验证Token有效性

先调用https://graph.microsoft.com/v1.0/me获取用户信息,若能正常返回数据,说明token有效,问题集中在Drive权限或端点匹配上。


内容的提问来源于stack exchange,提问作者user275472

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 18:51:07