You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter应用Firebase集成微软登录出现凭证格式错误/过期问题

解决Flutter + Firebase微软登录的AADSTS90023错误

错误核心原因

你遇到的AADSTS90023: Public clients can't send a client secret错误,本质是配置冲突:你的Flutter应用属于公共客户端(移动/桌面应用无法安全存储敏感密钥),但当前Azure AD和Firebase的配置中错误引入了客户端密钥,导致Firebase在向微软请求令牌时发送该密钥,触发Azure的安全拦截。

修复步骤

1. 删除Azure AD应用注册中的客户端密钥

  • 进入Azure门户,打开你的应用注册页面
  • 导航到「证书和机密」选项卡
  • 删除之前添加的所有客户端密钥(公共客户端模式下不需要此配置)

2. 修正Firebase微软身份提供者配置

  • 打开Firebase控制台,进入「Authentication」→「登录方法」→「Microsoft」
  • 只保留客户端ID的填写,清空「客户端密钥」输入框(公共客户端无需此参数)
  • 确认Firebase提供的重定向URL(如https://profiler-494e5.firebaseapp.com/__/auth/handler)已添加到Azure应用注册的「Web」平台下的重定向URL列表中

3. 优化Flutter登录代码(可选)

添加微软登录的基础权限范围,确保能获取用户基本信息:

Future<void> signInMicrosoft() async {
    final MicrosoftAuthProvider microsoftProvider = MicrosoftAuthProvider();
    // 添加必要的基础范围
    microsoftProvider.addScope("openid");
    microsoftProvider.addScope("profile");
    microsoftProvider.addScope("email");
    try {
      final UserCredential userCredential = await FirebaseAuth.instance.signInWithProvider(microsoftProvider);
      print(userCredential.additionalUserInfo);
    } on FirebaseAuthException catch (exception) {
      log("${exception.message}");
    }
  }

4. 配置Android平台的回调(针对移动端)

Android平台无需手动设置自定义重定向URL,只需在android/app/src/main/AndroidManifest.xml中添加Firebase自动生成的身份验证过滤器:

<intent-filter>
    <action android:name="android.intent.action.VIEW" />
    <category android:name="android.intent.category.DEFAULT" />
    <category android:name="android.intent.category.BROWSABLE" />
    <!-- 替换为你的Firebase项目对应的scheme,可从Firebase控制台获取 -->
    <data android:scheme="com.googleusercontent.apps.你的项目ID" />
</intent-filter>

你也可以通过运行flutterfire configure命令,让Firebase自动帮你配置Android的回调参数。

内容的提问来源于stack exchange,提问作者Senthur Kumaran

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.21 04:45:24