You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

BAS可调用但Workzone Launchpad调用失败:Microsoft Graph API令牌获取403问题

解决Workzone Launchpad中调用Cloud Foundry Destination获取Microsoft Graph令牌时的403错误

核心结论:从应用路由器应用路径获取的X-Csrf-Token对外部API请求无效

CSRF令牌与特定域/服务路径绑定,应用自身路径的令牌无法用于Destination代理的外部API请求,必须从目标请求的代理路径获取对应令牌。

解决方案步骤

1. 确认Destination配置正确性

确保Cloud Foundry Destination已正确配置Microsoft Graph相关信息:

  • 设置ProxyType=Internet
  • 填写正确的OAuth2认证参数(Client ID、Client Secret、Token Endpoint等)
  • 开启HTML5.DynamicDestination=true(若为动态调用场景)

2. 从Destination代理路径获取有效CSRF令牌

Workzone的应用路由器对POST请求强制CSRF校验,需先向Destination代理的令牌端点发起HEAD/GET请求获取对应令牌:

// 示例:获取CSRF令牌
async function getCsrfToken() {
  const destinationPath = "/destination/<你的Microsoft Graph Destination名称>/oauth2/token";
  const response = await fetch(destinationPath, {
    method: "HEAD",
    credentials: "include" // 必须携带,确保会话关联
  });
  return response.headers.get("X-Csrf-Token");
}

3. 携带CSRF令牌发起POST请求

拿到令牌后,在调用令牌端点的POST请求中携带X-Csrf-Token头,同时符合OAuth2请求格式:

async function fetchGraphToken() {
  const csrfToken = await getCsrfToken();
  const destinationPath = "/destination/<你的Microsoft Graph Destination名称>/oauth2/token";
  const formData = new URLSearchParams();
  formData.append("grant_type", "client_credentials");
  formData.append("scope", "https://graph.microsoft.com/.default");

  const response = await fetch(destinationPath, {
    method: "POST",
    headers: {
      "X-Csrf-Token": csrfToken,
      "Content-Type": "application/x-www-form-urlencoded"
    },
    body: formData,
    credentials: "include"
  });

  if (!response.ok) {
    throw new Error(`请求失败: ${response.status}`);
  }
  return response.json();
}

4. 排查Workzone权限配置

  • 确保Workzone中你的应用已被授予访问Cloud Foundry Destination服务的权限
  • 确认Destination的访问权限已对应用所在的空间/租户开放

关键说明

  • BAS环境无严格的CSRF强制校验,因此直接请求可成功;但Workzone的应用路由器默认启用CSRF保护,必须遵循令牌获取流程。
  • 不要直接调用Microsoft Graph的原始令牌端点,必须通过Cloud Foundry Destination的代理路径发起请求,避免跨域问题和权限拦截。

内容的提问来源于stack exchange,提问作者Athul Ram

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 04:15:14