You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android应用使用AppAuth实现Microsoft/Azure OAuth登录后登出无法重定向回应用的问题求助

Azure AD AppAuth登出后无法自动重定向回Android应用的解决方案

你完全不需要手动关闭Chrome标签页,这个问题主要是重定向配置缺失和登出结果处理逻辑不正确导致的,下面是具体的排查和修复步骤:

1. 确认Azure应用注册的关键配置

首先要确保你的Azure应用注册已经正确配置了登出重定向URI:

  • 登录Azure门户,进入你的应用注册 → 身份验证页面
  • 在"前端/移动和桌面应用"区域,添加oauth.playground://callback这个URI(和你登录用的重定向URI一致),并且勾选"ID令牌"选项(因为登出流程需要id_token_hint参数)
  • 注意:Azure AD v2.0的post_logout_redirect_uri必须预先在门户配置,否则会被忽略,这是很多开发者踩坑的点

2. 补全AndroidManifest的Intent过滤器

你的应用需要捕获oauth.playground://callback这个URI的重定向请求,所以要在MainActivity的标签里添加对应的intent-filter:

<activity android:name=".MainActivity">
    <intent-filter>
        <action android:name="android.intent.action.MAIN" />
        <category android:name="android.intent.category.LAUNCHER" />
    </intent-filter>
    <!-- 添加这个过滤器来捕获登出重定向 -->
    <intent-filter>
        <action android:name="android.intent.action.VIEW" />
        <category android:name="android.intent.category.DEFAULT" />
        <category android:name="android.intent.category.BROWSABLE" />
        <data 
            android:scheme="oauth.playground" 
            android:host="callback" />
    </intent-filter>
</activity>

3. 修正登出端点的配置

你当前用的是common租户的登出端点,建议和登录用的特定租户保持一致,避免跨租户的会话问题:

// 原来的common端点
// private val endSessionEndpoint = "https://login.microsoftonline.com/common/oauth2/v2.0/logout"
// 修改为和登录一致的租户端点
private val endSessionEndpoint = "https://login.microsoftonline.com/5445bade-1c6c-45cf-b87a-f21276046af6/oauth2/v2.0/logout"

4. 修复登出结果的处理逻辑

AppAuth的登出流程不会通过RESULT_OK返回结果,而是通过Intent传递EndSessionResponse,所以要修改onActivityResult里的RC_LOGOUT分支:

RC_LOGOUT -> {
    val endSessionResponse = EndSessionResponse.fromIntent(data)
    val exception = AuthorizationException.fromIntent(data)
    
    // 只要没有异常,或者拿到了登出响应,就认为登出成功
    if (exception == null || endSessionResponse != null) {
        authState.reset() // 重置AuthState,清除会话信息
        textEmail.text = null
        btnLogin.visibility = View.VISIBLE
        btnLogout.visibility = View.GONE
        Toast.makeText(this, "Logout successful", Toast.LENGTH_SHORT).show()
    } else {
        Toast.makeText(this, "Logout failed: ${exception.message}", Toast.LENGTH_SHORT).show()
    }
}

5. 增加登出前的有效性检查

确保登出时id_token_hint是有效的,避免空指针:

private fun logout() {
    if (authState.idToken.isNullOrEmpty()) {
        Toast.makeText(this, "No active session found", Toast.LENGTH_SHORT).show()
        return
    }
    
    val endSessionRequest = EndSessionRequest.Builder(authState.authorizationServiceConfiguration!!)
        .setIdTokenHint(authState.idToken)
        .setPostLogoutRedirectUri(Uri.parse(redirectUrl))
        .build()
    val endSessionIntent: Intent = authService.getEndSessionRequestIntent(endSessionRequest)
    startActivityForResult(endSessionIntent, RC_LOGOUT)
}

做完这些修改后,登出流程应该就能自动重定向回你的应用,不需要手动关闭浏览器标签了。

内容的提问来源于stack exchange,提问作者Egis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 19:04:13