如何利用Microsoft Graph API按passwordCredentials/endDateTime对应用排序
问题:使用Microsoft Graph API按passwordCredentials.endDateTime排序应用不可行,如何优先获取即将过期的应用?
我目前在用Microsoft Graph API获取应用的id、keyCredentials、passwordCredentials等信息,但没法按passwordCredentials/endDateTime字段对应用排序——毕竟endDateTime是嵌套在passwordCredentials里的多层结构。我想优先拿到即将过期的应用,请问这个需求能实现吗?
我试过在查询里加&$orderby参数,比如:
https://graph.microsoft.com/v1.0/applications?$select=id,keyCredentials,passwordCredentials&$orderby=displayName
但返回了错误:
{ "error": { "code": "Request_UnsupportedQuery", "message": "Sorting not supported for 'Application'.", "innerError": { "date": "2024-04-17T18:51:22", "request-id": "f31287e1-0105-463e-8611-b80c495ae67c", "client-request-id": "edcaa30c-6ee2-c876-b331-c7570345a5d1" } } }
返回的应用信息示例:
{ "value": [ { "id": "00000000-0000-0000-0000-00000001", "displayName": "account name 1", "passwordCredentials": [ { "customKeyIdentifier": null, "displayName": "Testing 1", "endDateTime": "2023-11-15T20:55:22.571Z", "hint": "akW", "keyId": "00000000-0000-0000-0000-00000001", "secretText": null, "startDateTime": "2023-05-19T19:55:22.571Z" }, { "customKeyIdentifier": null, "displayName": null, "endDateTime": "2119-05-09T16:43:05.4628335Z", "hint": "P49", "keyId": "00000000-0000-0000-0000-00000002", "secretText": null, "startDateTime": "2019-05-09T16:43:05.4628335Z" } ] }, { "id": "00000000-0000-0000-0000-00000002", "displayName": "account name 2", "passwordCredentials": [ { "customKeyIdentifier": null, "displayName": "Testing 2", "endDateTime": "2025-01-29T22:25:40.768Z", "hint": "9Oz", "keyId": "00000000-0000-0000-0000-00000002", "secretText": null, "startDateTime": "2023-01-30T22:25:40.768Z" } ] } ] }
解决方案
通过Graph API直接对applications集合按嵌套的passwordCredentials.endDateTime排序是不可行的,从返回的错误Request_UnsupportedQuery也能明确:当前Graph API不支持对Application资源的任何字段做排序操作。
要实现“优先获取即将过期的应用”的需求,只能在客户端完成排序逻辑,步骤如下:
- 先通过Graph API获取所有目标应用的完整数据(包含
passwordCredentials字段):https://graph.microsoft.com/v1.0/applications?$select=id,displayName,passwordCredentials - 在客户端对返回的应用列表进行处理:
- 对每个应用,找出其
passwordCredentials中最早过期的endDateTime(以此作为该应用的排序依据,确保即将过期的应用排在前面) - 将所有应用按这个“最早过期时间”升序排列
- 对每个应用,找出其
举个JavaScript示例代码:
// 假设response是Graph API返回的JSON数据 const apps = response.value; // 处理每个应用,添加最早过期时间字段 const appsWithEarliestExpiry = apps.map(app => { if (!app.passwordCredentials || app.passwordCredentials.length === 0) { // 无密码凭据的应用,设置极晚时间放在最后 return { ...app, earliestExpiry: new Date('9999-12-31') }; } // 找出当前应用下最早过期的凭据时间 const earliestExpiry = app.passwordCredentials.reduce((minDate, cred) => { const currentDate = new Date(cred.endDateTime); return currentDate < minDate ? currentDate : minDate; }, new Date('9999-12-31')); return { ...app, earliestExpiry }; }); // 按最早过期时间升序排序 appsWithEarliestExpiry.sort((a, b) => a.earliestExpiry - b.earliestExpiry); // 排序后的结果即为优先显示即将过期的应用 console.log(appsWithEarliestExpiry);
额外注意事项:
- 如果需要同时考虑
keyCredentials(证书凭据)的过期时间,可在处理逻辑中加入对keyCredentials.endDateTime的判断 - 若应用数量较多,建议使用Graph API的分页功能(
$top和$skip)分批获取数据,避免单次请求数据量过大影响性能
内容的提问来源于stack exchange,提问作者whisk
相关产品推荐
相关产品推荐

