You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决NHibernate配置Azure托管身份登录Azure数据库的认证错误?

解决NHibernate连接Azure SQL托管身份认证报错的思路

问题背景

使用Azure托管身份登录Azure SQL数据库,通过NHibernate的MsSqlConfiguration.MsSql2005配置连接,连接字符串包含Authentication=Active Directory Default参数时,抛出Invalid Value for key 'authentication'的配置异常。

核心原因

旧版NHibernate的SQL Server配置提供者(如MsSql2005)依赖的底层驱动(多为System.Data.SqlClient)不支持Azure AD专属的Authentication连接字符串参数,这类参数是后续Microsoft.Data.SqlClient新增的特性。

解决思路

1. 升级NHibernate及SQL驱动版本

  • 改用NHibernate提供的新版SQL Server配置项,比如MsSqlConfiguration.MsSqlServer(适配最新SQL Server特性),或对应Azure SQL兼容的版本(如MsSql2012及以上)。
  • 确保项目引用Microsoft.Data.SqlClient NuGet包(而非旧版System.Data.SqlClient),新版驱动原生支持Azure AD认证参数。
  • 修改后的代码示例:
FluentConfiguration fluent = Fluently.Configure()
    .Database(
        MsSqlConfiguration.MsSqlServer
            .ConnectionString(c => c.Is(connstring))
    );

2. 自定义连接提供者手动处理认证

若无法升级依赖,可通过自定义IConnectionProvider绕过连接字符串参数限制,手动注入托管身份令牌:

  • 实现IConnectionProvider接口,在GetConnection方法中创建SqlConnection,并设置Azure AD认证令牌:
public class AzureAdConnectionProvider : IConnectionProvider
{
    private string _connectionString;

    public void Configure(IDictionary<string, string> settings)
    {
        _connectionString = settings["connection.connection_string"];
    }

    public IDbConnection GetConnection()
    {
        var connection = new SqlConnection(_connectionString);
        // 获取托管身份令牌(需引用Azure.Identity包)
        var credential = new DefaultAzureCredential();
        var token = credential.GetToken(new TokenRequestContext(new[] { "https://database.windows.net/.default" }));
        connection.AccessToken = token.Token;
        connection.Open();
        return connection;
    }

    public void CloseConnection(IDbConnection conn)
    {
        if (conn != null && conn.State != ConnectionState.Closed)
        {
            conn.Close();
        }
    }

    public void Dispose()
    {
        // 清理资源
    }
}
  • 在NHibernate配置中指定自定义连接提供者:
FluentConfiguration fluent = Fluently.Configure()
    .Database(
        MsSqlConfiguration.MsSql2005
            .ConnectionString(c => c.Is(connstring))
            .ConnectionProvider<AzureAdConnectionProvider>()
    );

3. 验证连接字符串兼容性

  • 移除连接字符串中的Authentication=Active Directory Default参数,改为通过驱动的默认认证逻辑处理(需确保运行环境已配置托管身份权限)。
  • 确认连接字符串仅保留核心参数:Server=demo-server.database.windows.net,1433;Encrypt=True;Database=DEMO,依赖自定义连接提供者注入令牌完成认证。

内容的提问来源于stack exchange,提问作者Jennifer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.02 08:23:55