在Kusto中使用http_request_post插件获取Bearer Token的可行性及替代方案咨询
问题解答
你的理解是否正确?
你的理解完全正确。OAuth 2.0标准中,/oauth2/token端点(包括微软Defender等主流服务的实现)要求请求的Content-Type必须为application/x-www-form-urlencoded,且请求体需以key=value的键值对格式传递参数。如果http_request_post插件硬编码了application/json的Content-Type,发送的请求会因为格式不符合要求被端点拒绝。
可行替代方案
替换为支持自定义请求头的HTTP插件
放弃当前的http_request_post插件,选择允许手动配置请求头的HTTP请求工具/插件。这类工具可以直接设置Content-Type: application/x-www-form-urlencoded,并将授权参数(如client_id、grant_type等)拼接成key1=value1&key2=value2的格式放入请求体。编写自定义脚本构造请求
如果你的环境支持自定义代码执行,可以直接绕过插件,用脚本构造符合要求的请求:- PowerShell示例:
$tokenUrl = "https://your-oauth-endpoint/oauth2/token" $requestBody = @{ client_id = "你的客户端ID" client_secret = "你的客户端密钥" grant_type = "client_credentials" # 根据你的授权流调整,比如authorization_code scope = "所需权限范围" } $tokenResponse = Invoke-RestMethod -Uri $tokenUrl -Method Post -Body $requestBody -ContentType "application/x-www-form-urlencoded" $bearerToken = $tokenResponse.access_token - Python示例:
import requests token_endpoint = "https://your-oauth-endpoint/oauth2/token" payload = { "client_id": "你的客户端ID", "client_secret": "你的客户端密钥", "grant_type": "client_credentials", "scope": "所需权限范围" } response = requests.post(token_endpoint, data=payload) bearer_token = response.json().get("access_token")
- PowerShell示例:
修改现有插件源码(若有权限)
如果你能获取http_request_post插件的源码,可以修改硬编码Content-Type的部分,添加一个可配置项,让用户能根据需求切换application/json或application/x-www-form-urlencoded类型。
内容的提问来源于stack exchange,提问作者dueland
相关产品推荐
相关产品推荐

