Swagger集成Microsoft Entra ID授权仅Firefox可用,Edge/Chrome无响应求助
Swagger集成Microsoft Entra ID授权异常问题
我有一个集成Swagger的API,通过Microsoft Entra ID实现授权。该功能仅在Firefox浏览器中正常工作,在Edge和Chrome浏览器中点击Swagger的“授权”按钮后,页面一直处于等待状态无任何反应。当前已启用CORS:policy.AllowAnyOrigin().AllowAnyHeader().AllowAnyMethod();Swagger注册的重定向URL为https://localhost:7215/swagger/oauth2-redirect.html。
更新1:配置信息
以下是appsettings.json和Program.cs的配置内容:
appsettings.json
{ "AzureAd": { "Instance": "https://login.microsoftonline.com/", "Domain": "domain.onmicrosoft.com", "TenantId": "tenentid", "ClientId": "clientid", "CallbackPath": "/signin-oidc", "Scopes": "access_as_user", }, "SwaggerAzureAD": { "AuthorizationUrl": "https://login.microsoftonline.com/tenentid/oauth2/v2.0/authorize", "TokenUrl": "https://login.microsoftonline.com/tenentid/oauth2/v2.0/token", "Scope": "api://clientid/access_as_user", "ClientId": "swaggerclientid" }, "MicrosoftGraph": { "BaseUrl": "https://graph.microsoft.com/v1.0", "Scopes": "user.read" } }
Program.cs
builder.Services.AddAuthentication( JwtBearerDefaults.AuthenticationScheme) .AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd")) .EnableTokenAcquisitionToCallDownstreamApi() .AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph")) .AddInMemoryTokenCaches(); builder.Services.AddSwaggerGen(c => { c.SwaggerDoc("v1", new OpenApiInfo { Title = "Swagger API", Version = "v1", Description = "Oauth2.0 which uses AuthorizationCode flow", Contact = new OpenApiContact { Name = "name", Email = "email", } }); c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme { Description = "Oauth2.0 which uses AuthorizationCode flow", Name = "oauth2.0", Type = SecuritySchemeType.OAuth2, Flows = new OpenApiOAuthFlows { Implicit = new OpenApiOAuthFlow() { AuthorizationUrl = new Uri(config.SwaggerAzureAD.AuthorizationUrl), TokenUrl = new Uri(config.SwaggerAzureAD.TokenUrl), Scopes = new Dictionary<string, string> { {config.SwaggerAzureAD.Scope, "Access API as User"} } } } }); c.AddSecurityRequirement(new OpenApiSecurityRequirement { { new OpenApiSecurityScheme { Reference = new OpenApiReference{Type=ReferenceType.SecurityScheme, Id="oauth2"} }, new []{config.SwaggerAzureAD.Scope} } }); }); app.UseSwagger(); app.UseSwaggerUI(options => { options.OAuthAppName("Swagger Client"); options.OAuthClientId(config.SwaggerAzureAD.ClientId); options.OAuthUsePkce(); options.OAuthScopeSeparator(" "); });
更新2:客户端密钥配置修正
将appsettings.json中AzureAD部分的客户端密钥声明从:
"ClientSecret": "xxxxx"
修改为:
"ClientCredentials": [ { "SourceType": "ClientSecret", "ClientSecret": "xxxxx" } ]
修改后,AADSTS7000215错误已解决,但Edge和Chrome浏览器在授权后仍会卡住。
更新3:问题范围定位
该问题仅在我的机器上出现,推测可能是组策略(Group Policy)导致的。
内容的提问来源于stack exchange,提问作者sada
相关产品推荐
相关产品推荐

