已分配Basic许可证的Azure DevOps应用注册定期失效问题求助
问题现象
我配置了一个应用注册(Application Registration),通过REST API以编程方式读取Azure DevOps中的信息。初始状态功能正常:已在Azure DevOps组织级为其分配Basic许可证,并在相关项目中授予Project Reader角色,可正常扫描仓库。但几天后自动化功能失效,仅能通过将该用户从DevOps组织中完全删除再重新添加来恢复,修改或重新分配许可证、项目权限等操作均无效。本次正常访问持续了9天,此前类似案例为7-9天,最后正常访问日期为2月15日。调用REST API时无报错,显示账户已正常连接,但无法访问任何资源。
相关PowerShell代码
获取Bearer令牌的函数
function Get-BearerTokenFromDevOps ([string]$secret) { $body = @{ client_id = $clientId scope = "499b84ac-1321-427f-aa17-267ca6975798/.default" #API Permission: Azure Devops "User Impersonation", value of Resource App ID & /.default client_secret = $secret grant_type = "client_credentials" } $result = Invoke-RestMethod -Method Post -Uri "https://login.microsoftonline.com/<TENANT REMOVED>/oauth2/v2.0/token" -ContentType "application/x-www-form-urlencoded" -Body $body if ($null -ne $result.access_token) { return $result.access_token.ToString() } else { Write-Error "Received invalid response to OAuth query. Terminating script..." throw } }
获取已认证用户ID的函数
function Get-AuthenticatedUserId { $connectedUser = Get-FromDevOpsURL "https://app.vssps.visualstudio.com/_apis/ConnectionData" if ($null -ne $connectedUser -and $null -ne $connectedUser.Content) { $connectedUser = ConvertFrom-Json $connectedUser.Content return $connectedUser.authenticatedUser.id } }
获取账户列表的函数
function Get-AccountListFromDevOps([string]$userId) { $accountsListResponse = Get-FromDevOpsURL "https://app.vssps.visualstudio.com/_apis/accounts?api-version=6.0&memberId=$userId" if ($null -ne $accountsListResponse -and $null -ne $accountsListResponse.Content) { $accountsListResponse = ConvertFrom-Json $accountsListResponse.Content return $accountsListResponse.value } }
通用请求函数
function Get-FromDevOpsURL($url) { if ($null -eq $clientSecret) { throw } if($null -eq $script:bearerToken) { Write-Host "Getting Bearer Token" $script:bearerToken = (Get-BearerTokenFromDevOps -secret $clientSecret) } $headers = @{ "Authorization" = "Bearer $script:bearerToken" } $response = $(Invoke-WebRequest $url -Headers $headers) return $response }
重现时的错误
Invoke-RestMethod: {"$id":"1","innerException":null,"message":"ClaimsIdentity中缺少类型为'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier'或'http://schemas.microsoft.com/accesscontrolservice/2010/07/claims/identityprovider'的声明。要在基于声明的身份验证中启用防伪令牌支持,请验证配置的声明提供程序是否在其生成的ClaimsIdentity实例上提供这两个声明。如果配置的声明提供程序使用不同的声明类型作为唯一标识符,可以通过设置静态属性AntiForgeryConfig.UniqueClaimTypeIdentifier进行配置。","typeName":"System.InvalidOperationException, mscorlib","typeKey":"InvalidOperationException","errorCode":0,"eventId":0}
(附PowerShell 7.4运行报错截图)
内容的提问来源于stack exchange,提问作者user3012708

