更新Microsoft Graph后DelegateAuthenticationProvider缺失,如何创建Graph认证提供者?
在Microsoft Graph 5.x版本中创建AuthenticationProvider的替代方案
问题背景
在Microsoft Graph 4.54.0版本中,以下代码可正常运行:
var authProvider = new DelegateAuthenticationProvider(async (request) => { // Use Microsoft.Identity.Client to retrieve token var assertion = new UserAssertion(token.AccessToken); var result = await clientApplication.AcquireTokenOnBehalfOf(scopes, assertion).ExecuteAsync(); request.Headers.Authorization = new System.Net.Http.Headers.AuthenticationHeaderValue("Bearer", result.AccessToken); });
但升级到Microsoft Graph 5.0.0和Microsoft.Graph.Core 3.0.0版本后,会出现DelegateAuthenticationProvider找不到的错误,需要替换为新版本的认证实现方式。
解决方案
Microsoft Graph 5.x(配套Microsoft.Graph.Core 3.x)移除了DelegateAuthenticationProvider,推荐使用以下两种方式实现自定义认证:
方式1:继承BaseBearerTokenAuthenticationProvider实现自定义认证类
这种方式适合需要复用认证逻辑的场景:
using Microsoft.Graph; using Microsoft.Graph.Authentication; using Microsoft.Identity.Client; using System.Threading; using System.Threading.Tasks; public class OnBehalfOfAuthProvider : BaseBearerTokenAuthenticationProvider { private readonly IConfidentialClientApplication _clientApp; private readonly string[] _scopes; private readonly string _userAccessToken; public OnBehalfOfAuthProvider(IConfidentialClientApplication clientApp, string[] scopes, string userAccessToken) : base(new TokenCredentialAuthProvider()) { _clientApp = clientApp; _scopes = scopes; _userAccessToken = userAccessToken; } protected override async Task<string> GetAuthorizationTokenAsync(Uri uri, Dictionary<string, object>? additionalContext = null, CancellationToken cancellationToken = default) { var userAssertion = new UserAssertion(_userAccessToken); var authResult = await _clientApp.AcquireTokenOnBehalfOf(_scopes, userAssertion) .ExecuteAsync(cancellationToken); return authResult.AccessToken; } }
使用该类初始化GraphServiceClient:
// 初始化机密客户端应用(根据实际配置修改) var confidentialClient = ConfidentialClientApplicationBuilder .Create("你的客户端ID") .WithClientSecret("你的客户端密钥") .WithTenantId("你的租户ID") .Build(); var targetScopes = new[] { "https://graph.microsoft.com/.default" }; var userToken = "用户的访问令牌"; // 传入用户的原始访问令牌 var authProvider = new OnBehalfOfAuthProvider(confidentialClient, targetScopes, userToken); var graphClient = new GraphServiceClient(authProvider);
方式2:直接使用BearerTokenAuthenticationProvider(简化版)
如果不需要复用认证逻辑,可直接通过委托方式传入令牌获取逻辑:
using Microsoft.Graph; using Microsoft.Graph.Authentication; using Microsoft.Identity.Client; // 初始化机密客户端应用 var confidentialClient = ConfidentialClientApplicationBuilder .Create("你的客户端ID") .WithClientSecret("你的客户端密钥") .WithTenantId("你的租户ID") .Build(); var targetScopes = new[] { "https://graph.microsoft.com/.default" }; var userToken = "用户的访问令牌"; var authProvider = new BearerTokenAuthenticationProvider(async (requestContext) => { var userAssertion = new UserAssertion(userToken); var authResult = await confidentialClient.AcquireTokenOnBehalfOf(targetScopes, userAssertion) .ExecuteAsync(); return authResult.AccessToken; }); var graphClient = new GraphServiceClient(authProvider);
内容的提问来源于stack exchange,提问作者Shiraz Bhaiji
相关产品推荐
相关产品推荐

