SharePoint文件夹访问401授权失败问题求助(附Python代码)
问题描述
通过Python代码的客户端凭证流成功获取Azure AD访问令牌,但访问指定SharePoint Online文件夹时返回401未授权错误。代码及执行输出如下:
import requests #replace the following with your own values client_id = "12345" client_secret = "aabbccc" tenant_id = "12345aabbcc" resource = "https://vestas.sharepoint.com/" #get the access token auth_url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/token" data = { "client_id": client_id, "client_secret": client_secret, "resource": resource, "grant_type": "client_credentials", } response = requests.post(auth_url, data=data) if response.status_code == 200: auth_response = response.json() access_token = auth_response["access_token"] print("Access token obtained:", access_token) else: print("Failed to obtain access token, status code:", response.status_code) #Replace the placeholder with the actual SharePoint API endpoint api_endpoint = "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/Shared Documents/General/Files for BI" headers = { "Authorization": "Bearer " + access_token, "Accept": "application/json;odata=verbose" } response = requests.get(api_endpoint, headers=headers) #Check if the request was successful if response.status_code == 200: data = response.json() print("Authorization successful") #Do something with the data obtained from the API else: print("Authorization failed, status code:", response.status_code)
执行输出:
Access token obtained: eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ii1LSTNROW5OUjdiUm9meG1lWm9YcWJIWkdldyIsImtpZCI6Ii1LSTNROW5OUjd...... (an extended token) Authorization failed, status code: 401
解决方案
1. 修正API端点格式
直接访问文件夹的URL不是SharePoint REST API的规范路径,需替换为标准REST端点:
https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/_api/web/GetFolderByServerRelativeUrl('Shared Documents/General/Files for BI')
或完整相对路径写法:
https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/_api/web/GetFolderByServerRelativeUrl('/sites/DEP-TurbineEngineering-VAME/Shared Documents/General/Files for BI')
2. 确认Azure应用权限配置
- 必须使用应用权限:客户端凭证流不支持委托权限,需在Azure AD应用的API权限中添加SharePoint的
Sites.Read.All/Sites.ReadWrite.All应用权限,并完成管理员同意。 - 精细化权限控制(可选):若仅需访问特定站点,使用
Sites.Selected权限,再通过PowerShell为应用授予目标站点权限:Connect-PnPOnline -Url "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME" -Interactive Grant-PnPAzureADAppSitePermission -AppId "<你的client_id>" -DisplayName "应用名称" -Permissions Read -Site "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME"
3. 验证令牌受众匹配
解码本地获取的access token(用本地工具如jwt.io,无需上传第三方),确认aud字段值与代码中resource参数一致(即https://vestas.sharepoint.com/),受众不匹配会直接导致401。
4. 检查文件夹权限设置
确保目标文件夹未断开权限继承,或已显式添加Azure应用服务主体(名称为Azure应用名称)的读取权限。可在SharePoint站点的文件夹权限设置中手动添加并授权。
5. 优化请求头配置
补充Content-Type头,确保请求格式规范:
headers = { "Authorization": f"Bearer {access_token}", "Accept": "application/json;odata=verbose", "Content-Type": "application/json;odata=verbose" }
权限验证替代方法
PnP PowerShell测试:
Connect-PnPOnline -Url "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME" -ClientId "<client_id>" -ClientSecret "<client_secret>" -Tenant "<tenant_id>.onmicrosoft.com" Get-PnPFolder -Url "Shared Documents/General/Files for BI"若能返回文件夹信息,说明权限配置正常,问题出在代码API调用部分。
Graph API测试:
切换到Graph API验证权限,注意需将代码中resource参数改为https://graph.microsoft.com/,调用端点示例:graph_endpoint = "https://graph.microsoft.com/v1.0/sites/vestas.sharepoint.com,{site_id},{web_id}/drive/root:/Shared Documents/General/Files for BI" headers = { "Authorization": f"Bearer {access_token}", "Accept": "application/json" }
内容的提问来源于stack exchange,提问作者Ricardo Bullón Zegarra
相关产品推荐
相关产品推荐

