You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用client_id/client_secret查询Azure DevOps工作项返回登录页,如何解决?

Azure DevOps REST API 应用身份验证查询工作项失败问题

问题描述

使用带vso.work_write权限的PAT可正常通过Azure DevOps REST API查询工作项,但改用Microsoft Entra应用身份验证时,虽能成功获取access_token,执行WIQL查询却返回登录页面的HTML。已完成以下配置:

  • 在Azure门户的Microsoft Entra中创建新应用
  • 为应用分配vso.work_write权限并授予管理员同意
  • 创建client_secret
  • 将应用添加为Azure DevOps用户,分配目标项目的「Project Contributor」角色

使用的PowerShell代码如下:

# Define the variables
$organization = "..."
$project = "..."
$clientId = "..."
$tenantId = "..."
$clientSecret = "..."
$baseurl = "https://dev.azure.com/$organization/$project"
$tokenurl = "https://login.microsoftonline.com/$tenantId/oauth2/token"

# Get the access token
$body = @{
    client_id = $clientId
    client_secret = $clientSecret
    grant_type = "client_credentials"
    scope = "https://app.vssps.visualstudio.com/vso.work_write"
}
$tokenresponse = Invoke-RestMethod -Uri $tokenurl -Method Post -Body $body -ContentType "application/x-www-form-urlencoded"
$token = $tokenresponse.access_token
echo $tokenresponse # This looks fine

# Define the WIQL query
$wiql = @{
    query = "SELECT [System.Id], [System.AssignedTo], [System.State], [System.Title] FROM workitems WHERE [System.TeamProject] = '$project' AND [System.State] = 'Resolved' AND [System.ChangedDate] < @today-7 AND [System.Tags] NOT CONTAINS 'Stale'"
} | ConvertTo-Json

# Post the WIQL query to the REST API
$wiqlurl = "$baseurl/_apis/wit/wiql?api-version=7.1"
$wiqlresponse = Invoke-RestMethod -Uri $wiqlurl -Method Post -Body $wiql -ContentType "application/json" -Headers @{Authorization=("Bearer {0}" -f $token)}

echo $wiqlresponse # This is the html of the sign in page

解决方案

1. 修正令牌请求的Scope参数

客户端凭据模式下,Azure DevOps要求Scope使用https://dev.azure.com/{organization}/.default格式,而非具体权限值。修改令牌请求的body部分:

$body = @{
    client_id = $clientId
    client_secret = $clientSecret
    grant_type = "client_credentials"
    scope = "https://dev.azure.com/$organization/.default"
}

此模式下,Azure AD会根据应用已分配的权限自动生成包含所有必要权限的令牌,无需指定单个权限。

2. 确认应用的Azure DevOps权限生效

  • 登录Azure DevOps组织,进入「组织设置」→「用户」,搜索应用名称确认身份已正确添加
  • 检查目标项目的「权限」设置,确认应用已被分配「Project Contributor」角色,若刚配置需等待几分钟同步生效

3. 验证令牌有效性

用JWT解码工具解析获取到的access_token,查看scp或roles声明,确认包含vso.work_write权限,确保令牌具备所需访问权限。

4. 检查请求头格式

确保Authorization头严格为Bearer {token}格式,无多余空格或字符,当前代码中的写法是正确的,可再次核对。

内容的提问来源于stack exchange,提问作者wertzui

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 17:02:36