You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Swagger集成Microsoft Entra ID授权仅Firefox可用,Edge/Chrome无响应求助

Swagger集成Microsoft Entra ID授权异常问题

我有一个集成Swagger的API,通过Microsoft Entra ID实现授权。该功能仅在Firefox浏览器中正常工作,在Edge和Chrome浏览器中点击Swagger的“授权”按钮后,页面一直处于等待状态无任何反应。当前已启用CORS:policy.AllowAnyOrigin().AllowAnyHeader().AllowAnyMethod();Swagger注册的重定向URL为https://localhost:7215/swagger/oauth2-redirect.html。

更新1:配置信息

以下是appsettings.json和Program.cs的配置内容:

appsettings.json

{
  "AzureAd": {
    "Instance": "https://login.microsoftonline.com/",
    "Domain": "domain.onmicrosoft.com",
    "TenantId": "tenentid",
    "ClientId": "clientid",
    "CallbackPath": "/signin-oidc",
    "Scopes": "access_as_user",
  },
  "SwaggerAzureAD": {
    "AuthorizationUrl":       
 "https://login.microsoftonline.com/tenentid/oauth2/v2.0/authorize",
    "TokenUrl": 
 "https://login.microsoftonline.com/tenentid/oauth2/v2.0/token",
    "Scope": "api://clientid/access_as_user",
    "ClientId": "swaggerclientid"
  },
  "MicrosoftGraph": {
    "BaseUrl": "https://graph.microsoft.com/v1.0",
    "Scopes": "user.read"
  }
}

Program.cs

builder.Services.AddAuthentication(
  JwtBearerDefaults.AuthenticationScheme)
.AddMicrosoftIdentityWebApi(builder.Configuration.GetSection("AzureAd"))
.EnableTokenAcquisitionToCallDownstreamApi()
.AddMicrosoftGraph(builder.Configuration.GetSection("MicrosoftGraph"))
.AddInMemoryTokenCaches();

builder.Services.AddSwaggerGen(c =>
{
  c.SwaggerDoc("v1",
    new OpenApiInfo
    {
        Title = "Swagger API",
        Version = "v1",
        Description = "Oauth2.0 which uses AuthorizationCode flow",
        Contact = new OpenApiContact
        {
            Name = "name",
            Email = "email",
        }
    });

  c.AddSecurityDefinition("oauth2", new OpenApiSecurityScheme
  {
    Description = "Oauth2.0 which uses AuthorizationCode flow",
    Name = "oauth2.0",
    Type = SecuritySchemeType.OAuth2,
    Flows = new OpenApiOAuthFlows
    {
        Implicit = new OpenApiOAuthFlow()
        {
            AuthorizationUrl = new Uri(config.SwaggerAzureAD.AuthorizationUrl),
            TokenUrl = new Uri(config.SwaggerAzureAD.TokenUrl),
            Scopes = new Dictionary<string, string>
            {
                {config.SwaggerAzureAD.Scope, "Access API as User"}
            }
        }
    }
  });

  c.AddSecurityRequirement(new OpenApiSecurityRequirement
  {
    {
        new OpenApiSecurityScheme
        {
            Reference = new OpenApiReference{Type=ReferenceType.SecurityScheme, Id="oauth2"}
        },
        new []{config.SwaggerAzureAD.Scope}
    }
  });
});

app.UseSwagger();
app.UseSwaggerUI(options =>
{
  options.OAuthAppName("Swagger Client");
  options.OAuthClientId(config.SwaggerAzureAD.ClientId);
  options.OAuthUsePkce();
  options.OAuthScopeSeparator(" ");
});

更新2:客户端密钥配置修正

将appsettings.json中AzureAD部分的客户端密钥声明从:

"ClientSecret": "xxxxx"

修改为:

"ClientCredentials": [
  {
    "SourceType": "ClientSecret",
    "ClientSecret": "xxxxx"
  }
]

修改后,AADSTS7000215错误已解决,但Edge和Chrome浏览器在授权后仍会卡住。

更新3:问题范围定位

该问题仅在我的机器上出现,推测可能是组策略(Group Policy)导致的。


内容的提问来源于stack exchange,提问作者sada

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.08 00:17:45