You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何借助Windows Auth通过ASP.NET Web API访问Azure DevOps Server数据?

使用Windows身份认证调用Azure DevOps Server API的解决方案

你不需要从ClaimsPrincipal提取数据手动添加到请求头,Windows身份认证是通过NTLM/Kerberos协议传递身份的,核心是让请求自动携带当前已识别的Windows用户凭据到Azure DevOps Server。以下是两种可行方案:

方法1:使用HttpClient的默认凭据(推荐)

直接配置HttpClientHandler启用默认凭据,它会自动传递当前请求上下文的Windows用户身份:

using System.Net.Http;
using System.Net.Http.Headers;
using System.Threading.Tasks;

[HttpGet]
public async Task<string> Get()
{
    var userName = User.FindFirstValue(ClaimTypes.Name);
    
    // 配置HttpClient使用当前用户的Windows凭据
    using var handler = new HttpClientHandler { UseDefaultCredentials = true };
    using var httpClient = new HttpClient(handler);
    
    // 设置API接受JSON格式响应
    httpClient.DefaultRequestHeaders.Accept.Add(
        new MediaTypeWithQualityHeaderValue("application/json"));
    
    // 调用Azure DevOps Server项目列表API
    var apiUrl = "https://{azure}/{org}/_apis/projects?api-version=6.0";
    var response = await httpClient.GetAsync(apiUrl);
    
    return response.IsSuccessStatusCode 
        ? await response.Content.ReadAsStringAsync() 
        : $"请求失败:{response.StatusCode}";
}

关键注意事项

  • 若你的Web API托管在IIS,需确保应用程序池的身份具备委派权限,允许将用户身份传递到Azure DevOps Server。
  • Azure DevOps Server必须启用Windows身份认证,且信任Web API所在的服务器。

方法2:Windows身份模拟(复杂场景适配)

如果需要更精细控制身份传递流程,可以模拟当前用户的Windows身份发起请求:

using System.Net.Http;
using System.Net.Http.Headers;
using System.Security.Principal;
using System.Threading.Tasks;

[HttpGet]
public async Task<string> Get()
{
    var windowsIdentity = User.Identity as WindowsIdentity;
    if (windowsIdentity == null) return "未识别到Windows身份";
    
    // 模拟当前登录的Windows用户
    using (windowsIdentity.Impersonate())
    {
        using var handler = new HttpClientHandler { UseDefaultCredentials = true };
        using var httpClient = new HttpClient(handler);
        
        httpClient.DefaultRequestHeaders.Accept.Add(
            new MediaTypeWithQualityHeaderValue("application/json"));
        
        var apiUrl = "https://{azure}/{org}/_apis/projects?api-version=6.0";
        var response = await httpClient.GetAsync(apiUrl);
        
        return response.IsSuccessStatusCode 
            ? await response.Content.ReadAsStringAsync() 
            : $"请求失败:{response.StatusCode}";
    }
}

额外提示

  • 不要尝试手动构造身份相关的请求头,Windows身份认证依赖底层协议(NTLM/Kerberos)完成身份传递,手动添加头无法完成认证。
  • 跨服务器调用时,需确保Kerberos约束委派配置正确,否则会出现身份传递失败的问题(比如"双跳"问题)。

内容的提问来源于stack exchange,提问作者GranmaSquid3

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 13:32:33