获取OneDrive文件下载OAuth授权码及刷新令牌遇阻求助
问题描述
用户目标是下载个人OneDrive所有文件,但在通过Azure AD获取访问令牌时遇到两个问题:
授权码模式请求令牌时,提示缺少
code参数,不清楚该参数的定义及获取路径:
运行代码:import requests token_params = { 'client_id': 'ClientID', 'grant_type': 'authorization_code', 'scope': 'https://graph.microsoft.com/.default', 'client_secret': 'ClientSecret', 'redirect_uri': 'https://jwt.ms' } tenant = 'TenantID' token = requests.post(url=f'https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token', data=token_params)返回错误:
"error":"invalid_request","error_description":"AADSTS900144: The request body must contain the following parameter: 'code'.此前尝试刷新令牌模式,因
refresh_token为空导致失败:
运行代码:import requests params = { 'grant_type': 'refresh_token', 'client_id': 'ClientID', 'refresh_token': '' } response = requests.post('https://login.microsoftonline.com/common/oauth2/v2.0/token', data=params)返回错误:
"error":"invalid_request","error_description":"AADSTS900144: The request body must contain the following parameter: 'refresh_token'.
用户曾参考相关技术问答,但关联页面无法访问,急需解决令牌获取问题以推进文件下载任务。
解决方案
1. 明确核心参数作用
code:授权码,是用户完成身份验证并授权应用后,Azure AD返回的临时凭证,用于换取访问令牌(access_token)和刷新令牌(refresh_token)。refresh_token:长期凭证,用于在access_token过期后(默认1小时),无需用户重新登录即可获取新的access_token。
2. 完整流程:从获取令牌到下载文件
步骤1:注册Azure AD应用
- 登录Azure门户,搜索“应用注册”并创建新注册:
- 名称自定义;
- 支持账户类型选择“任何组织目录中的账户和个人Microsoft账户(例如Skype、Xbox)”;
- 重定向URI选择“Web”,填写
https://jwt.ms(需与后续代码保持一致);
- 注册完成后,记录客户端ID(client_id);在“证书和密码”菜单创建客户端密码(client_secret),务必保存该密码(仅显示一次)。
步骤2:获取授权码code
构造授权URL,替换YOUR_CLIENT_ID为你的客户端ID:
https://login.microsoftonline.com/common/oauth2/v2.0/authorize?client_id=YOUR_CLIENT_ID&response_type=code&redirect_uri=https://jwt.ms&scope=Files.Read.All offline_access
- 将URL复制到浏览器,用个人Microsoft账户登录并授权应用访问OneDrive;
- 跳转至
https://jwt.ms后,从浏览器地址栏提取code=xxxxxx部分的字符串,这就是所需的code。
步骤3:用code换取access_token和refresh_token
修改授权码模式代码,补充code参数:
import requests token_params = { 'client_id': '你的ClientID', 'grant_type': 'authorization_code', 'scope': 'Files.Read.All offline_access', 'client_secret': '你的ClientSecret', 'redirect_uri': 'https://jwt.ms', 'code': '从地址栏提取的code' } response = requests.post(url='https://login.microsoftonline.com/common/oauth2/v2.0/token', data=token_params) token_data = response.json() print(token_data) # 从中可获取access_token和refresh_token
步骤4:调用Graph API下载OneDrive文件
使用access_token请求文件列表并下载:
import requests access_token = token_data['access_token'] headers = {'Authorization': f'Bearer {access_token}'} # 获取根目录文件列表 folder_response = requests.get('https://graph.microsoft.com/v1.0/me/drive/root/children', headers=headers) files = folder_response.json().get('value', []) # 逐个下载文件 for file in files: if '@microsoft.graph.downloadUrl' in file: download_res = requests.get(file['@microsoft.graph.downloadUrl']) with open(file['name'], 'wb') as f: f.write(download_res.content) print(f"已下载:{file['name']}")
步骤5:用refresh_token刷新令牌
当access_token过期后,使用refresh_token获取新令牌:
refresh_params = { 'grant_type': 'refresh_token', 'client_id': '你的ClientID', 'refresh_token': token_data['refresh_token'], 'scope': 'Files.Read.All offline_access' } refresh_response = requests.post('https://login.microsoftonline.com/common/oauth2/v2.0/token', data=refresh_params) new_token_data = refresh_response.json() new_access_token = new_token_data['access_token'] new_refresh_token = new_token_data['refresh_token'] # 替换旧的refresh_token,下次刷新用这个
内容的提问来源于stack exchange,提问作者Saeed
相关产品推荐
相关产品推荐

