You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

C# Core应用调用SharePoint API遇403禁止错误及访问权限问题咨询

问题原因分析

浏览器访问SharePoint API时,依赖的是你已登录会话中的认证Cookie(如FedAuth),而C# Core程序无法直接复用这些浏览器会话Cookie。SharePoint的REST API要求请求携带有效的OAuth2访问令牌,而非浏览器会话的Cookie,因此即使你有成员权限,程序未正确认证也会返回403错误。

解决方案

以下是几种在.NET Core应用中访问SharePoint列表的有效认证方式:

1. 应用权限认证(Client Credentials Flow,无用户交互)

适合服务器端后台应用,通过Azure AD注册应用获取权限,无需用户登录。

步骤:

  • 在Azure门户中注册应用,添加SharePoint的应用权限(如Sites.Read.All、Sites.ReadWrite.All),并由管理员授予同意。
  • 获取应用的Client ID、Client Secret和租户ID。

代码示例:

using System.Net.Http;
using System.Net.Http.Headers;
using System.Threading.Tasks;
using System.Collections.Generic;
using System.Text.Json;

public async Task<string> FetchShareListItems()
{
    var tenantId = "你的租户ID";
    var clientId = "你的应用Client ID";
    var clientSecret = "你的应用Client Secret";
    var siteUrl = "https://你的租户.sharepoint.com/sites/你的站点";
    var listApiUrl = $"{siteUrl}/_api/web/lists/getbytitle('你的列表名称')/items";

    // 获取访问令牌
    using var tokenClient = new HttpClient();
    var tokenRequest = new FormUrlEncodedContent(new Dictionary<string, string>
    {
        ["grant_type"] = "client_credentials",
        ["client_id"] = clientId,
        ["client_secret"] = clientSecret,
        ["scope"] = $"{siteUrl}/.default"
    });

    var tokenResponse = await tokenClient.PostAsync(
        $"https://login.microsoftonline.com/{tenantId}/oauth2/v2.0/token", 
        tokenRequest
    );
    tokenResponse.EnsureSuccessStatusCode();
    var tokenData = JsonSerializer.Deserialize<Dictionary<string, string>>(
        await tokenResponse.Content.ReadAsStringAsync()
    );
    var accessToken = tokenData["access_token"];

    // 调用SharePoint API
    using var apiClient = new HttpClient();
    apiClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
    apiClient.DefaultRequestHeaders.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));

    var apiResponse = await apiClient.GetAsync(listApiUrl);
    apiResponse.EnsureSuccessStatusCode();
    return await apiResponse.Content.ReadAsStringAsync();
}

2. 用户权限认证(Authorization Code Flow,用户交互)

适合需要以当前用户身份访问的应用,通过OAuth2流程引导用户登录获取令牌。

代码示例(使用Microsoft.Identity.Client):

using Microsoft.Identity.Client;
using System.Net.Http;
using System.Net.Http.Headers;
using System.Threading.Tasks;

public async Task<string> FetchListItemsAsUser()
{
    var clientId = "你的应用Client ID";
    var tenantId = "你的租户ID";
    var siteUrl = "https://你的租户.sharepoint.com/sites/你的站点";
    var listApiUrl = $"{siteUrl}/_api/web/lists/getbytitle('你的列表名称')/items";
    var redirectUri = "http://localhost:5000"; // 应用的重定向URI

    var pca = PublicClientApplicationBuilder
        .Create(clientId)
        .WithTenantId(tenantId)
        .WithRedirectUri(redirectUri)
        .Build();

    var scopes = new[] { $"{siteUrl}/Sites.Read.All" };
    var authResult = await pca.AcquireTokenInteractive(scopes).ExecuteAsync();
    var accessToken = authResult.AccessToken;

    using var apiClient = new HttpClient();
    apiClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", accessToken);
    apiClient.DefaultRequestHeaders.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));

    var apiResponse = await apiClient.GetAsync(listApiUrl);
    apiResponse.EnsureSuccessStatusCode();
    return await apiResponse.Content.ReadAsStringAsync();
}

3. 使用PnP Core SDK(简化开发)

PnP Core SDK封装了SharePoint API的调用和认证逻辑,降低开发复杂度。

步骤:

  • 安装NuGet包:PnP.Core和PnP.Core.Auth。

代码示例:

using PnP.Core.Model.SharePoint;
using PnP.Core.Services;
using System.Collections.Generic;
using System.Threading.Tasks;

public async Task<List<IListItem>> GetListItemsWithPnP()
{
    var siteUrl = "https://你的租户.sharepoint.com/sites/你的站点";
    var clientId = "你的应用Client ID";
    var clientSecret = "你的应用Client Secret";
    var tenantId = "你的租户ID";

    var authProvider = new ClientCredentialsAuthenticationProvider(clientId, clientSecret, tenantId);
    using var context = await PnPContextFactory.CreateAsync(siteUrl, authProvider);

    var targetList = await context.Web.Lists.GetByTitleAsync("你的列表名称");
    var items = await targetList.Items.GetAsync();

    return items.ToList();
}
排查要点
  • 确认应用权限已正确配置并获得管理员同意(应用权限模式)。
  • 检查访问令牌的作用域是否包含目标站点的权限。
  • 验证API请求中的列表名称、站点URL是否拼写正确。
  • 使用Postman等工具测试带有效令牌的API请求,排除代码逻辑问题。

内容的提问来源于stack exchange,提问作者Sarubala M

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.07 04:45:43