You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已分配Basic许可证的Azure DevOps应用注册定期失效问题求助

Azure DevOps API访问周期性失效问题

问题现象

我配置了一个应用注册(Application Registration),通过REST API以编程方式读取Azure DevOps中的信息。初始状态功能正常:已在Azure DevOps组织级为其分配Basic许可证,并在相关项目中授予Project Reader角色,可正常扫描仓库。但几天后自动化功能失效,仅能通过将该用户从DevOps组织中完全删除再重新添加来恢复,修改或重新分配许可证、项目权限等操作均无效。本次正常访问持续了9天,此前类似案例为7-9天,最后正常访问日期为2月15日。调用REST API时无报错,显示账户已正常连接,但无法访问任何资源。

相关PowerShell代码

获取Bearer令牌的函数

function Get-BearerTokenFromDevOps ([string]$secret) {
    $body = @{
        client_id     = $clientId
        scope         = "499b84ac-1321-427f-aa17-267ca6975798/.default" #API Permission: Azure Devops "User Impersonation", value of Resource App ID & /.default
        client_secret = $secret
        grant_type    = "client_credentials"
    }
    $result = Invoke-RestMethod -Method Post -Uri "https://login.microsoftonline.com/<TENANT REMOVED>/oauth2/v2.0/token" -ContentType "application/x-www-form-urlencoded" -Body $body
    if ($null -ne $result.access_token) {
        return $result.access_token.ToString()
    } else {
        Write-Error "Received invalid response to OAuth query. Terminating script..."
        throw
    }
}

获取已认证用户ID的函数

function Get-AuthenticatedUserId {

    $connectedUser = Get-FromDevOpsURL "https://app.vssps.visualstudio.com/_apis/ConnectionData"

    if ($null -ne $connectedUser -and $null -ne $connectedUser.Content) {
        $connectedUser = ConvertFrom-Json $connectedUser.Content
        return $connectedUser.authenticatedUser.id
    }
}

获取账户列表的函数

function Get-AccountListFromDevOps([string]$userId) {
    $accountsListResponse = Get-FromDevOpsURL "https://app.vssps.visualstudio.com/_apis/accounts?api-version=6.0&memberId=$userId"
    if ($null -ne $accountsListResponse -and $null -ne $accountsListResponse.Content) {
        $accountsListResponse = ConvertFrom-Json $accountsListResponse.Content
        return $accountsListResponse.value
    }
}

通用请求函数

function Get-FromDevOpsURL($url)
{
        if ($null -eq $clientSecret)
        { 
            throw
        }

        if($null -eq $script:bearerToken)
        {
            Write-Host "Getting Bearer Token"
            $script:bearerToken = (Get-BearerTokenFromDevOps -secret $clientSecret)
        }
        $headers = @{ "Authorization" = "Bearer $script:bearerToken" }
        $response = $(Invoke-WebRequest $url -Headers $headers)

    return $response
}

重现时的错误

Invoke-RestMethod: {"$id":"1","innerException":null,"message":"ClaimsIdentity中缺少类型为'http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier'或'http://schemas.microsoft.com/accesscontrolservice/2010/07/claims/identityprovider'的声明。要在基于声明的身份验证中启用防伪令牌支持,请验证配置的声明提供程序是否在其生成的ClaimsIdentity实例上提供这两个声明。如果配置的声明提供程序使用不同的声明类型作为唯一标识符,可以通过设置静态属性AntiForgeryConfig.UniqueClaimTypeIdentifier进行配置。","typeName":"System.InvalidOperationException, mscorlib","typeKey":"InvalidOperationException","errorCode":0,"eventId":0}

(附PowerShell 7.4运行报错截图)

内容的提问来源于stack exchange,提问作者user3012708

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 11:22:06