You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用自定义Scope时Azure AD登录失败:用户信息响应无效

Azure AD切换自定义Scope后登录失败问题

原正常配置

以下Azure AD登录配置可正常运行:

security:
  oauth2:
    client:
      provider:
        azure-active-directory:
          issuer-uri: ${OAUTH2_ISSUER}
      registration:
        api-gateway:
          provider: azure-active-directory
          authorization-grant-type: authorization_code
          redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
          client-id: ${OAUTH2_CLIENT_ID}
          client-secret: ${OAUTH2_CLIENT_SECRET}
          scope: openid

问题触发操作

将配置中的scope替换为Azure AD中新建的自定义Scope:

scope: api://my-id-removed/jango-test-api

错误现象

  1. 登录后自动跳转至login?error路由
  2. 应用日志显示用户信息端点读取异常:
2023-10-10T00:51:24.151+02:00 DEBUG 50489 --- [ctor-http-nio-7] athPatternParserServerWebExchangeMatcher : 检查请求匹配:'/login/oauth2/code/azure';匹配路径'/login/oauth2/code/{registrationId}'
2023-10-10T00:51:25.078+02:00 DEBUG 50489 --- [ctor-http-nio-6] o.s.s.w.s.a.AuthenticationWebFilter      : 认证失败:[invalid_user_info_response] 读取UserInfo响应时发生错误:[invalid_user_info_response]
  1. 直接访问用户信息端点返回如下错误:
{
  "error": {
    "code": "InvalidAuthenticationToken",
    "message": "访问令牌为空。",
    "innerError": {
      "date": "2023-10-09T22:58:11",
      "request-id": "7e7a3bc8-7fb5-4bdb-a648-bfd4bf6f2dc8",
      "client-request-id": "7e7a3bc8-7fb5-4bdb-a648-bfd4bf6f2dc8"
    }
  }
}

内容的提问来源于stack exchange,提问作者user5228754

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.09 04:02:23