单租户Bot调用Skill遇IDX10208错误的配置咨询
关于Bot Framework单租户模式下技能调用的身份验证问题
我在Bot Emulator中使用单租户模式,通过App ID和密码运行Bot技能示例,起初持续遇到Unauthorized错误。查阅文档后添加以下配置解决了该错误:
{ "OAuthUrl": "https://unitedstates.api.botframework.com", "ToChannelFromBotOAuthScope": "https://api.botframework.com", "ToChannelFromBotLoginUrlTemplate": "https://api.botframework.com", "PublicAzureChannel": "https://api.botframework.com", "ToBotFromChannelOpenIdMetadataUrl": "https://login.botframework.com/v1/.well-known/openidconfiguration", "ToBotFromEmulatorOpenIdMetadataUrl": "https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration", "ToBotFromChannelTokenIssuer": "https://api.botframework.com", "ToChannelFromBotLoginUrl": "https://login.microsoftonline.com/botframework.com" }
但调用Skill时出现如下错误:
"label": "TurnError", "valueType": "https://www.botframework.com/schemas/error", "value": "System.Net.Http.HttpRequestException: Error invoking the skill id: "label": "TurnError", "valueType": "https://www.botframework.com/schemas/error", "value": "System.Net.Http.HttpRequestException: Error invoking the skill id: \"EchoSkillBot\" at \"http://localhost:39783/api/messages\" (status is 500). Microsoft.IdentityModel.Tokens.SecurityTokenInvalidAudienceException: IDX10208: Unable to validate audience. validationParameters.ValidAudience is null or whitespace and validationParameters.ValidAudiences is null. at Microsoft.IdentityModel.Tokens.Validators.ValidateAudience(IEnumerable1 audiences, SecurityToken securityToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateTokenPayload(JwtSecurityToken jwtToken, TokenValidationParameters validationParameters) at System.IdentityModel.Tokens.Jwt.JwtSecurityTokenHandler.ValidateToken(String token, TokenValidationParameters validationParameters, SecurityToken& validatedToken) at Microsoft.Bot.Connector.Authentication.JwtTokenExtractor.ValidateTokenAsync(String jwtToken, String channelId, String[] requiredEndorsements) at Microsoft.Bot.Connector.Authentication.JwtTokenExtractor.GetIdentityAsync(String scheme, String parameter, String channelId, String[] requiredEndorsements) at Microsoft.Bot.Connector.Authentication.JwtTokenExtractor.GetIdentityAsync(String authorizationHeader, String channelId, String[] requiredEndorsements) at Microsoft.Bot.Connector.Authentication.ParameterizedBotFrameworkAuthentication.SkillValidation_AuthenticateChannelTokenAsync(String authHeader, String channelId, CancellationToken cancellationToken) at Microsoft.Bot.Connector.Authentication.ParameterizedBotFrameworkAuthentication.JwtTokenValidation_AuthenticateTokenAsync(String authHeader, String channelId, String serviceUrl, CancellationToken cancellationToken) at Microsoft.Bot.Connector.Authentication.ParameterizedBotFrameworkAuthentication.JwtTokenValidation_ValidateAuthHeaderAsync(String authHeader, String channelId, String serviceUrl, CancellationToken cancellationToken) at Microsoft.Bot.Connector.Authentication.ParameterizedBotFrameworkAuthentication.JwtTokenValidation_AuthenticateRequestAsync(Activity activity, String authHeader, CancellationToken cancellationToken) at Microsoft.Bot.Connector.Authentication.ParameterizedBotFrameworkAuthentication.AuthenticateRequestAsync(Activity activity, String authHeader, CancellationToken cancellationToken) at Microsoft.Bot.Builder.CloudAdapterBase.ProcessActivityAsync(String authHeader, Activity activity, BotCallbackHandler callback, CancellationToken cancellationToken) at Microsoft.Bot.Builder.Integration.AspNet.Core.CloudAdapter.ProcessAsync(HttpRequest httpRequest, HttpResponse httpResponse, IBot bot, CancellationToken cancellationToken) at Microsoft.BotBuilderSamples.EchoSkillBot.Controllers.BotController.PostAsync() in D:\bot\bot\80.skills-simple-bot-to-bot\EchoSkillBot\Controllers\BotController.cs:line 30 at lambda_method4(Closure , Object ) at Microsoft.AspNetCore.Mvc.Infrastructure.ActionMethodExecutor.AwaitableResultExecutor.Execute(IActionResultTypeMapper mapper, ObjectMethodExecutor executor, Object controller, Object[] arguments) at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.<InvokeActionMethodAsync>g__Logged|12_1(ControllerActionInvoker invoker) at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.<InvokeNextActionFilterAsync>g__Awaited|10_0(ControllerActionInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.Rethrow(ActionExecutedContextSealed context) at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.Next(State& next, Scope& scope, Object& state, Boolean& isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ControllerActionInvoker.<InvokeInnerFilterAsync>g__Awaited|13_0(ControllerActionInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeFilterPipelineAsync>g__Awaited|20_0(ResourceInvoker invoker, Task lastTask, State next, Scope scope, Object state, Boolean isCompleted) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker) at Microsoft.AspNetCore.Mvc.Infrastructure.ResourceInvoker.<InvokeAsync>g__Logged|17_1(ResourceInvoker invoker) at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|6_0(Endpoint endpoint, Task requestTask, ILogger logger) at Microsoft.AspNetCore.Authorization.AuthorizationMiddleware.Invoke(HttpContext context) at Microsoft.AspNetCore.Diagnostics.DeveloperExceptionPageMiddleware.Invoke(HttpContext context)
我不清楚此处的有效受众配置具体指什么,现咨询两个问题:
- 如何确保配置正确使用单租户模式,无需启用应用授权中的多租户支持?
- 需要提供哪些有效受众,以及可在何处配置这些受众?
内容的提问来源于stack exchange,提问作者Sam
相关产品推荐
相关产品推荐

