You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SharePoint文件夹访问401授权失败问题求助(附Python代码)

问题描述

通过Python代码的客户端凭证流成功获取Azure AD访问令牌,但访问指定SharePoint Online文件夹时返回401未授权错误。代码及执行输出如下:

import requests

#replace the following with your own values 
client_id = "12345" 
client_secret = "aabbccc" 
tenant_id = "12345aabbcc" 
resource = "https://vestas.sharepoint.com/"

#get the access token 
auth_url = f"https://login.microsoftonline.com/{tenant_id}/oauth2/token" 
data = { 
"client_id": client_id, "client_secret": client_secret, "resource": resource, "grant_type": "client_credentials",
}

response = requests.post(auth_url, data=data) 
if response.status_code == 200: 
    auth_response = response.json() 
    access_token = auth_response["access_token"] 
    print("Access token obtained:", access_token) 

else: 
    print("Failed to obtain access token, status code:", response.status_code)

#Replace the placeholder with the actual SharePoint API endpoint 
api_endpoint = "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/Shared Documents/General/Files for BI"

headers = { "Authorization": "Bearer " + access_token, "Accept": "application/json;odata=verbose" }

response = requests.get(api_endpoint, headers=headers)

#Check if the request was successful 
if response.status_code == 200: 
    data = response.json() 
    print("Authorization successful")

#Do something with the data obtained from the API 
else: 
    print("Authorization failed, status code:", response.status_code)

执行输出:

Access token obtained: eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ii1LSTNROW5OUjdiUm9meG1lWm9YcWJIWkdldyIsImtpZCI6Ii1LSTNROW5OUjd...... (an extended token)
Authorization failed, status code: 401
解决方案

1. 修正API端点格式

直接访问文件夹的URL不是SharePoint REST API的规范路径,需替换为标准REST端点:

https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/_api/web/GetFolderByServerRelativeUrl('Shared Documents/General/Files for BI')

或完整相对路径写法:

https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME/_api/web/GetFolderByServerRelativeUrl('/sites/DEP-TurbineEngineering-VAME/Shared Documents/General/Files for BI')

2. 确认Azure应用权限配置

  • 必须使用应用权限:客户端凭证流不支持委托权限,需在Azure AD应用的API权限中添加SharePoint的Sites.Read.All/Sites.ReadWrite.All应用权限,并完成管理员同意。
  • 精细化权限控制(可选):若仅需访问特定站点,使用Sites.Selected权限,再通过PowerShell为应用授予目标站点权限:
    Connect-PnPOnline -Url "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME" -Interactive
    Grant-PnPAzureADAppSitePermission -AppId "<你的client_id>" -DisplayName "应用名称" -Permissions Read -Site "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME"
    

3. 验证令牌受众匹配

解码本地获取的access token(用本地工具如jwt.io,无需上传第三方),确认aud字段值与代码中resource参数一致(即https://vestas.sharepoint.com/),受众不匹配会直接导致401。

4. 检查文件夹权限设置

确保目标文件夹未断开权限继承,或已显式添加Azure应用服务主体(名称为Azure应用名称)的读取权限。可在SharePoint站点的文件夹权限设置中手动添加并授权。

5. 优化请求头配置

补充Content-Type头,确保请求格式规范:

headers = {
    "Authorization": f"Bearer {access_token}",
    "Accept": "application/json;odata=verbose",
    "Content-Type": "application/json;odata=verbose"
}
权限验证替代方法
  • PnP PowerShell测试:

    Connect-PnPOnline -Url "https://vestas.sharepoint.com/sites/DEP-TurbineEngineering-VAME" -ClientId "<client_id>" -ClientSecret "<client_secret>" -Tenant "<tenant_id>.onmicrosoft.com"
    Get-PnPFolder -Url "Shared Documents/General/Files for BI"
    

    若能返回文件夹信息,说明权限配置正常,问题出在代码API调用部分。

  • Graph API测试:
    切换到Graph API验证权限,注意需将代码中resource参数改为https://graph.microsoft.com/,调用端点示例:

    graph_endpoint = "https://graph.microsoft.com/v1.0/sites/vestas.sharepoint.com,{site_id},{web_id}/drive/root:/Shared Documents/General/Files for BI"
    headers = {
        "Authorization": f"Bearer {access_token}",
        "Accept": "application/json"
    }
    

内容的提问来源于stack exchange,提问作者Ricardo Bullón Zegarra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 13:55:38