.NET 7机密客户端应用适配MS Graph v5:身份验证提供者选型
适配MS Graph v5的认证提供者替换方案
在MS Graph v5版本中,DelegateAuthenticationProvider已被移除,针对你使用**客户端凭证(Client Secret)**的服务端场景,需要使用ClientCredentialProvider来替代。
修改后的完整代码如下:
using Microsoft.Graph; using Microsoft.Identity.Client; public static class GraphConfiguration { public static IServiceCollection ConfigureGraphComponent( this IServiceCollection services, IConfiguration configuration ) { var graphConfig = configuration.GetSection("AzureAD"); var confidentialClientApplication = ConfidentialClientApplicationBuilder .Create(graphConfig["ClientId"]) .WithTenantId(graphConfig["Tenant"]) .WithClientSecret(graphConfig["ClientSecret"]) .Build(); // 替换为ClientCredentialProvider,指定Graph默认作用域 var authenticationProvider = new ClientCredentialProvider( confidentialClientApplication, new[] { "https://graph.microsoft.com/.default" } ); // 应用生命周期内使用单例GraphServiceClient services.AddSingleton(sp => new GraphServiceClient(authenticationProvider)); return services; } }
关键说明:
ClientCredentialProvider是MS Graph v5官方推荐的服务端场景认证提供者,会自动处理令牌的获取与附加逻辑https://graph.microsoft.com/.default作用域表示使用Azure AD中为该应用注册的所有已配置应用权限,符合服务端到服务端的授权模式- 确保项目已安装
Microsoft.Graphv5.x版本的NuGet包
内容的提问来源于stack exchange,提问作者Eric
相关产品推荐
相关产品推荐

