使用Easy Auth与Identity Server时,如何用访问令牌访问Azure Function?
解决方案
1. 从Identity Server同时获取id_token和access_token
密码授权模式下,无需依赖浏览器,只要在请求connect/token时指定openid scope,就能同时拿到id_token和access_token。请求参数示例:
POST /connect/token Content-Type: application/x-www-form-urlencoded grant_type=password &username=你的用户名 &password=你的密码 &client_id=你的客户端ID &client_secret=你的客户端密钥 &scope=openid 你的API scope(比如api/function)
响应里会包含id_token、access_token等字段。
2. 用id_token+access_token完成Easy Auth验证
向Azure Function的授权端点https://example.net/.auth/login/TestProvider发送POST请求,Body里同时传入两个令牌:
{ "id_token": "从token端点拿到的id_token", "access_token": "从token端点拿到的access_token" }
请求成功后,会返回包含authenticationToken的响应,这个就是访问Azure Function需要的令牌。
3. 访问Azure Function
调用Function接口时,在请求头里带上:
Authorization: Bearer <返回的authenticationToken>
关键注意事项
- 确保Identity Server的客户端配置中,
AllowedGrantTypes包含Password,AllowedScopes包含openid和你Function对应的API scope - 全程无需走浏览器的
/connect/authorize流程,密码授权是纯后台调用,符合无浏览器访问的需求
内容的提问来源于stack exchange,提问作者MilleB
相关产品推荐
相关产品推荐

