Azure应用调用Microsoft Graph API访问共享文件夹遇403权限拒绝
访问公开共享OneDrive文件夹时的403权限拒绝问题解决
问题现象
调用Microsoft Graph API访问公开共享的OneDrive文件夹时返回403错误:
Fatal error: Uncaught GuzzleHttp\Exception\ClientException: Client error: `GET https://graph.microsoft.com/v1.0/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL2Yvcy FBdHVBTV9OYWN3VmFoaUZwdU1HU19CaVFDd1d1/root?expand=children` resulted in a `403 Forbidden` response: {"error":{"code":"accessDenied","message":"The sharing link no longer exists, or you do not have permission to access it." ,"innerError":{"date":"2023-10-11T05:01:49","request-id":"27bd1fc1- 74f8-4d8d-9a43-41a3aa6a9f02","client-request-id":"27bd1fc1-74f8-4d8d-9a43 -41a3aa6a9f02"}}}
该共享链接在浏览器中可正常访问,但应用调用时被拒绝。当前应用的Access Token已包含以下权限:
{ "appid": "563e2470-8b86-48dc-9050-20228336584e", "appidacr": "1", "idp": "https://sts.windows.net/74162350-5947-4628-892f-4ee1d28d88cc/", "idtyp": "app", "oid": "d9b6b299-ddc2-4708-ac87-2a48beb896f4", "rh": "0.AUIAUCMWdEdZKEaJL07h0o2IzAMAAAAAAAAAwAAAAAAAAACkAAA.", "roles": [ "Application.ReadWrite.All", "Sites.Read.All", "Application.Read.All" ], "sub": "d9b6b299-ddc2-4708-ac87-2a48beb896f4", "tenant_region_scope": "OC", "tid": "74162350-5947-4628-892f-4ee1d28d88cc", "uti": "rJQ_ra77J0ux9XBeCvMIAA", "ver": "1.0", "wids": [ "0997a1d0-0d1d-4acb-b408-d5ca73121e90" ] }
调用代码片段(在->execute()处失败):
$guzzle = new \GuzzleHttp\Client(); $url = 'https://login.microsoftonline.com/' . $tenantId . '/oauth2/v2.0/token'; /* * If the client requests scope=https://graph.microsoft.com/.default, no consent prompt is shown, regardless of the contents of the client application's registered permissions for Microsoft Graph. The returned token contains the scopes Mail.Read and User.Read. */ $token = json_decode($guzzle->post($url, [ 'form_params' => [ 'client_id' => $clientId, 'scope' => 'https://graph.microsoft.com/.default', 'grant_type' => 'client_credentials', 'client_secret' => $clientSecret, ], ])->getBody()->getContents()); $accessToken = $token->access_token; $graph = new Graph(); $graph->setAccessToken($accessToken); $user = $graph->createRequest("GET", "/shares/u!aHR0cHM6Ly8xZHJ2Lm1zL2YvcyFBdHVBTV9OYWN3VmFoaUZwdU1HU19CaVFDd1d1/root?expand=children") ->setReturnType(Microsoft\Graph\Model\DriveItem::class) ->execute();
问题分析与解决方法
- 核心权限缺失:当前应用权限列表中缺少
Files.Read.All应用权限。Sites.Read.All仅针对SharePoint站点内容,访问OneDrive共享文件/文件夹需要专门的文件权限。客户端凭据模式下必须添加Files.Read.All应用权限并完成管理员同意。 - 共享链接权限限制:确认共享链接是"任何人可访问"类型,若为"仅限组织内部",客户端凭据模式下的应用无法跨租户访问该资源。需调整共享链接权限为完全公开,或确保应用与共享资源属于同一租户。
- API调用验证:重新获取Access Token后,检查token的
roles字段是否包含Files.Read.All,确认权限已生效后再发起API请求。
操作步骤
- 登录Azure门户,进入目标应用注册页面,选择"API权限"选项卡。
- 点击"添加权限",选择"Microsoft Graph",再选择"应用权限",搜索并添加
Files.Read.All权限。 - 点击"授予管理员同意",确保权限生效。
- 重新运行代码获取新的Access Token,再次调用Graph API。
内容的提问来源于stack exchange,提问作者Alexander
相关产品推荐
相关产品推荐

