You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET MAUI应用实现ArcGIS Portal非交互式认证方案求助

.NET MAUI实现Azure AD登录后非交互式获取ArcGIS Portal令牌

核心思路

ArcGIS Portal配置Azure AD作为身份提供商后,支持JWT令牌交换流程:用已获取的Azure AD用户令牌,向ArcGIS Portal的令牌端点发起请求,直接换取ArcGIS的Bearer令牌,无需二次交互式登录。

步骤与代码示例

1. 配置MSAL并实现Azure AD交互式登录

使用MSAL库完成Azure AD交互式登录,获取用户的Bearer令牌:

安装依赖

在.NET MAUI项目中安装Microsoft.Identity.Client NuGet包。

登录代码示例

using Microsoft.Identity.Client;

public class AzureAdAuthService
{
    // 替换为你的Azure AD应用配置
    private const string ClientId = "你的Azure AD应用Client ID";
    private const string TenantId = "你的租户ID(如common或具体租户ID)";
    private const string RedirectUri = "msal{ClientId}://auth"; // MAUI中常用的重定向URI
    private readonly IPublicClientApplication _pca;

    public AzureAdAuthService()
    {
        _pca = PublicClientApplicationBuilder.Create(ClientId)
            .WithTenantId(TenantId)
            .WithRedirectUri(RedirectUri)
            .WithMauiRedirectUri(RedirectUri) // 针对MAUI的特殊配置
            .Build();
    }

    // 交互式登录获取Azure AD令牌
    public async Task<string> GetAzureAdAccessTokenAsync(string[] scopes)
    {
        var accounts = await _pca.GetAccountsAsync();
        AuthenticationResult result;

        try
        {
            // 尝试静默登录(如果已有缓存的令牌)
            result = await _pca.AcquireTokenSilent(scopes, accounts.FirstOrDefault())
                .ExecuteAsync();
        }
        catch (MsalUiRequiredException)
        {
            // 静默失败,发起交互式登录
            result = await _pca.AcquireTokenInteractive(scopes)
                .WithParentActivityOrWindow(MauiProgram.CurrentActivity) // MAUI需要传递当前窗口上下文
                .ExecuteAsync();
        }

        return result.AccessToken;
    }
}

2. 非交互式交换ArcGIS Portal令牌

拿到Azure AD的令牌后,向ArcGIS Portal的令牌端点发送POST请求,换取ArcGIS令牌:

令牌交换代码示例

using System.Net.Http;
using System.Text.Json;

public class ArcGisAuthService
{
    private readonly HttpClient _httpClient;
    // 替换为你的ArcGIS Portal地址
    private const string ArcGisPortalUrl = "https://你的ArcGIS Portal地址/portal/sharing/rest";

    public ArcGisAuthService()
    {
        _httpClient = new HttpClient();
    }

    // 用Azure AD令牌交换ArcGIS令牌
    public async Task<string> GetArcGisAccessTokenAsync(string azureAdToken)
    {
        var tokenEndpoint = $"{ArcGisPortalUrl}/oauth2/token";

        var requestContent = new FormUrlEncodedContent(new Dictionary<string, string>
        {
            ["grant_type"] = "jwt",
            ["client_id"] = "arcgis", // ArcGIS Portal中Azure AD IDP对应的客户端ID,默认是arcgis,可在Portal配置中确认
            ["jwt_token"] = azureAdToken,
            ["f"] = "json"
        });

        var response = await _httpClient.PostAsync(tokenEndpoint, requestContent);
        response.EnsureSuccessStatusCode();

        var responseJson = await response.Content.ReadFromJsonAsync<JsonElement>();
        return responseJson.GetProperty("access_token").GetString();
    }
}

3. 整合流程调用

在MAUI页面或ViewModel中整合两个步骤:

private async Task CompleteAuthFlow()
{
    // 1. 交互式登录获取Azure AD令牌(内部API所需的scopes)
    var azureAdService = new AzureAdAuthService();
    var azureAdToken = await azureAdService.GetAzureAdAccessTokenAsync(new[] { "api://你的内部API ID/access_as_user" });

    // 2. 非交互式交换ArcGIS令牌
    var arcGisService = new ArcGisAuthService();
    var arcGisToken = await arcGisService.GetArcGisAccessTokenAsync(azureAdToken);

    // 后续使用azureAdToken调用内部API,arcGisToken调用ArcGIS服务
}

关键注意事项

  • ArcGIS Portal配置验证:确保Azure AD身份提供商已正确配置在ArcGIS Portal中,且client_id参数与Portal中设置的一致(可在Portal的https://<portal-url>/portal/sharing/rest/info端点查看)。
  • Azure AD令牌权限:Azure AD应用需要被授权访问ArcGIS Portal对应的Azure AD应用(可在Azure AD的API权限中添加对应权限)。
  • MAUI上下文传递:调用AcquireTokenInteractive时必须传递当前窗口上下文(WithParentActivityOrWindow),否则登录弹窗可能无法正常显示。

内容的提问来源于stack exchange,提问作者dik1977

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 16:15:43