ReportPhishingCommandSurface调用OfficeRuntime.auth.getAccessToken遇SSO 5001错误
问题:ReportPhishingCommandSurface扩展点调用OfficeRuntime.auth.getAccessToken报SSO 5001错误
在基于ReportPhishingCommandSurface扩展点的POC中,调用OfficeRuntime.auth.getAccessToken获取访问令牌用于Graph API请求时,始终返回错误:SSO failed with "5001" error code.,无额外错误信息。
环境基于官方示例搭建,仅修改调用函数以触发getAccessToken。
补充信息
- Azure门户中有两个配置完全一致的应用:一个是标准插件,点击按钮触发
getAccessToken可正常运行;另一个基于ReportPhishingCommandSurface,出现上述5001错误。
额外细节
- 可捕获到对
/.well-known/microsoft-officeaddins-allowed.json的请求,内容如下:
{ "allowed": [ "https://localhost:3000/command/command.js", "https://localhost:3000/command/command.html", ] }
- 相关URL已添加到Azure的“单页应用程序”允许列表中;
- 清单文件包含
WebApplicationInfo节:
<WebApplicationInfo> <Id>[redacted]</Id> <Resource>api://localhost:3000/[redacted]</Resource> <Scopes> <Scope>openid</Scope> <Scope>profile</Scope> <Scope>email</Scope> <Scope>User.Read</Scope> <Scope>Mail.Read</Scope> <Scope>Mail.ReadWrite</Scope> <Scope>Mail.Send</Scope> </Scopes> </WebApplicationInfo>
调用代码
const defaultSSO = { allowSignInPrompt: false, allowConsentPrompt: false, }; function onSpamReport(event) { const options = JSON.parse(JSON.stringify(defaultSSO)); // Begin promise chain. return OfficeRuntime.auth.getAccessToken(options).then((accessToken) => { console.log('getAccessToken done'); console.log('accesstoken: ' + accessToken); //<- 永远无法执行到这里 ...
日志记录
20/09/2023 15:13:59 Verbose Runtime [Console] [Log] SDX Control is ready! 20/09/2023 15:13:59 Verbose Runtime [Console] [Log] onSpamReport 20/09/2023 15:13:59 Verbose Runtime [Console] [Log] MailboxHostExecuteApi invoked! 20/09/2023 15:13:59 Verbose Runtime [Console] [Log] RunLaunchEventHandlerFunctionWithData was invoked with funcName = onSpamReport 20/09/2023 15:13:59 Verbose Runtime [Console] [Log] callWebServerAPI(POST, https://localhost:3000/report_phishing) 20/09/2023 15:13:59 Verbose Runtime [Console] [Log] MailboxHostExecuteApi invoked! 20/09/2023 15:13:59 Monitorable WebApplicationInfo SSO failed with "5001" error code.
解决思路
1. 检查扩展点的SSO支持限制
ReportPhishingCommandSurface属于预览版扩展点,可能存在SSO特殊限制:
- 邮件报告场景的触发上下文下,Office客户端可能未完全初始化SSO所需环境;
- 先将
allowSignInPrompt和allowConsentPrompt设为true,强制触发登录/授权流程,验证基础流程是否可行(即使POC需要静默SSO,先排除流程问题)。
修改后的代码示例:
const defaultSSO = { allowSignInPrompt: true, allowConsentPrompt: true, };
2. 验证Azure应用权限配置
虽然两个应用配置一致,仍需确认ReportPhishing扩展对应的Azure应用:
- 确保
api://localhost:3000/[redacted]资源标识符与Azure应用“Expose an API”中的配置完全匹配; - 检查应用是否已完成
User.Read等所需权限的管理员同意流程(即使标准插件已同意,该应用需单独完成)。
3. 核对清单文件扩展点配置
确认ReportPhishingCommandSurface扩展点的CommandExtension中,SourceLocation指向的URL已加入microsoft-officeaddins-allowed.json和Azure允许列表。
4. 排查客户端环境问题
- 在最新Office预览版客户端中测试,预览版扩展点可能仅在特定版本支持SSO;
- 清除Office客户端缓存,重新加载插件后重试。
内容的提问来源于stack exchange,提问作者Plann1n3
相关产品推荐
相关产品推荐

