You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft登录未返回Refresh Token,如何获取长效令牌?

解决MSAL.js获取Refresh Token实现长效访问的问题

核心问题分析

你遇到的问题是SPA场景下未正确获取/使用refresh token,虽然添加了offline_access权限,但存在配置或代码调用的疏漏,导致无法实现长效登录。

修复步骤

1. 修正Azure应用注册配置

  • 确认你的应用注册类型为单页应用(SPA):在Azure门户的应用注册中,进入“身份验证”页面,检查重定向URI的类型是否为“单页应用”,而非“Web”。SPA类型的应用才会在授权流程中返回refresh token。
  • 确认offline_access权限已完成授权:
    • 租户内应用需确保管理员已同意该权限;
    • 多租户应用需确保用户登录时已同意包含offline_access的权限范围。

2. 修正前端MSAL代码

你的现有代码存在两个关键问题:loginRedirect参数中多余的grant_type(该参数仅适用于后端授权码流程),以及缺少缓存配置导致refresh token无法持久化。

修正后的代码示例:

// 初始化MSAL实例,补充完整配置
const msalInstance = new msal.PublicClientApplication({
    auth: {
        clientId: '<client-id>',
        redirectUri: window.location.origin, // 需与Azure应用注册的重定向URI完全一致
        authority: 'https://login.microsoftonline.com/common' // 多租户用common,单租户替换为租户ID
    },
    cache: {
        cacheLocation: 'localStorage', // 持久化存储refresh token,关闭浏览器后仍可复用
        storeAuthStateInCookie: false // SPA场景下建议关闭,IE兼容需求除外
    }
});

// 登录跳转,移除无效的grant_type参数
msalInstance.loginRedirect({
    scopes: ['user.read', 'calendars.readwrite', 'offline_access', 'openid']
});

3. 使用静默方式自动刷新令牌

登录成功后,后续调用API时需通过acquireTokenSilent获取令牌,MSAL会自动判断令牌是否过期,若过期则自动使用refresh token刷新:

async function getAccessToken() {
    const account = msalInstance.getAllAccounts()[0];
    if (!account) {
        msalInstance.loginRedirect({ scopes: ['user.read', 'calendars.readwrite', 'offline_access', 'openid'] });
        return;
    }

    try {
        const response = await msalInstance.acquireTokenSilent({
            account: account,
            scopes: ['user.read', 'calendars.readwrite']
        });
        return response.accessToken;
    } catch (error) {
        if (error instanceof msal.InteractionRequiredAuthError) {
            // 静默刷新失败,触发交互式授权(无需重新输入密码,基于SSO)
            await msalInstance.acquireTokenRedirect({
                account: account,
                scopes: ['user.read', 'calendars.readwrite']
            });
        } else {
            throw error;
        }
    }
}

4. 验证Refresh Token存储状态

可以通过以下代码查看refresh token是否被正确存储:

const cache = msalInstance.getCacheStorage();
const refreshTokens = cache.getAllRefreshTokens();
console.log('存储的Refresh Tokens:', refreshTokens);

若能输出有效内容,说明配置已生效,MSAL会自动处理令牌刷新逻辑。

关键注意事项

  • SPA场景下,refresh token由MSAL自动管理,无需手动存储或调用刷新接口;
  • 确保浏览器允许本地存储(localStorage),否则无法持久化refresh token,用户关闭浏览器后需重新登录;
  • Azure AD中SPA的refresh token最长有效期为90天,过期后会触发交互式重新授权,用户仅需确认登录即可,无需重复输入密码。

内容的提问来源于stack exchange,提问作者Sohayb Saleh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 15:15:31