本地运行Angular代码时遇AADSTS900561错误求助
解决Angular中AADSTS900561错误:登出端点收到GET请求而非POST/OPTIONS
AADSTS900561错误的核心原因是你调用的Microsoft Entra ID https://login.microsoftonline.com/common/oauth2/v2.0/logoutsession/ 端点仅接受POST或OPTIONS请求,但你的Angular应用发起了GET请求。以下是针对性的解决方法:
方法1:使用MSAL库的内置登出方法(推荐)
如果你使用@azure/msal-angular作为认证库,不要直接通过URL跳转发起登出(这会触发GET请求),而是调用库提供的logoutRedirect方法,它会自动处理POST请求:
import { MsalService } from '@azure/msal-angular'; constructor(private msalService: MsalService) {} handleLogout(): void { this.msalService.logoutRedirect({ postLogoutRedirectUri: 'https://127.0.0.1:8007' // 匹配你配置的重定向URL }); }
方法2:确认应用注册的登出重定向URL配置
登录Microsoft Entra ID门户,找到你的应用注册:
- 进入身份验证页面
- 在前端平台下,确保
https://127.0.0.1:8007已添加为登出重定向URL(不是仅作为登录重定向URL) - 注意地址要和代码中完全一致,包括协议、IP和端口
方法3:自定义POST请求实现登出(无MSAL库时)
如果是手动实现登出逻辑,需要创建隐藏表单通过POST方式提交到logout端点,避免GET请求:
handleLogout(): void { const logoutForm = document.createElement('form'); logoutForm.method = 'POST'; logoutForm.action = 'https://login.microsoftonline.com/common/oauth2/v2.0/logoutsession/'; logoutForm.target = '_self'; // 添加登出后重定向参数 const redirectInput = document.createElement('input'); redirectInput.type = 'hidden'; redirectInput.name = 'post_logout_redirect_uri'; redirectInput.value = 'https://127.0.0.1:8007'; logoutForm.appendChild(redirectInput); document.body.appendChild(logoutForm); logoutForm.submit(); document.body.removeChild(logoutForm); }
内容的提问来源于stack exchange,提问作者Arjun Dhilod
相关产品推荐
相关产品推荐

