使用MSAL遇AADSTS65001错误,调整范围后现401身份验证问题
MSAL授权问题及后续API验证异常求助
我使用MSAL已有近三年时间,目前遇到一个无法解决的问题,即便查阅了大量相关帖子:
"AADSTS65001: The user or administrator has not consented to use the application with ID 'c09036af-fd62-4db6-b27a-xxxxxxxxxxxx' named 'mySite.com'. Send an interactive authorization request for this user and resource. Trace ID: 126a546f-a8b3-4176-8c74-e6a4c4851300 Correlation ID: 6cc0a067-ec3b-4b25-9caa-215620991f24 Timestamp: 2023-06-28 08:14:16Z"
我知道这是Azure应用授权相关问题,但关键是当前无需进行授权操作,“已配置权限”下没有待授予的未决同意项。我的应用是独立应用,无关联API应用。问题可能出在范围上,此前我一直使用clientId作为范围,但此次该方式无效。
有人有解决思路吗?
补充测试结果
经过测试后我确认问题确实出在范围上。按照@Rukmini的建议,我将范围设置为{clientId}/default,现在登录功能正常,但同域下的API出现以下错误:
401 oidc: id token issued by a different provider, expected "https://login.microsoftonline.com/9c0a3ae0-3f12-4197-a76d-xxxxxxxxxxxx/v2.0" got "https://sts.windows.net/9c0a3ae0-3f12-4197-a76d-xxxxxxxxxxxx/" []
内容的提问来源于stack exchange,提问作者Emaborsa
相关产品推荐
相关产品推荐

