如何通过用户名、密码或Token绕过SharePoint站点登录页(Java方案)
一、基于用户名+密码的NTLM身份验证
很多内部部署的SharePoint站点采用NTLM认证机制,直接通过HTTP请求携带NTLM凭证即可跳过登录页。Java中可借助Apache HttpClient的NTLM支持快速实现。
依赖引入
<!-- Apache HttpClient --> <dependency> <groupId>org.apache.httpcomponents</groupId> <artifactId>httpclient</artifactId> <version>4.5.14</version> </dependency>
实现代码
import org.apache.http.auth.AuthScope; import org.apache.http.auth.NTCredentials; import org.apache.http.client.CredentialsProvider; import org.apache.http.client.methods.CloseableHttpResponse; import org.apache.http.client.methods.HttpGet; import org.apache.http.impl.client.BasicCredentialsProvider; import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.HttpClients; import org.apache.http.util.EntityUtils; public class SharePointNTLMAuth { public static void main(String[] args) throws Exception { String sharePointUrl = "https://your-sharepoint-site.com/sites/your-site/_api/web/lists"; String username = "domain\\user"; // 格式:域名\用户名 String password = "your-password"; String workstation = ""; // 留空或填写本地机器名 String domain = "your-domain"; // 配置NTLM凭证 CredentialsProvider credsProvider = new BasicCredentialsProvider(); credsProvider.setCredentials( new AuthScope(AuthScope.ANY_HOST, AuthScope.ANY_PORT), new NTCredentials(username, password, workstation, domain) ); // 创建HttpClient并发送请求 try (CloseableHttpClient httpClient = HttpClients.custom() .setDefaultCredentialsProvider(credsProvider) .build()) { HttpGet request = new HttpGet(sharePointUrl); request.addHeader("Accept", "application/json;odata=verbose"); try (CloseableHttpResponse response = httpClient.execute(request)) { String responseBody = EntityUtils.toString(response.getEntity()); System.out.println(responseBody); } } } }
二、基于用户名+密码的OAuth 2.0认证(适用于SharePoint Online)
SharePoint Online依托Azure AD提供OAuth 2.0支持,可使用MSAL4J库通过用户名密码流(ROPC)获取Token,再携带Token请求接口跳过登录页。
依赖引入
<!-- MSAL4J --> <dependency> <groupId>com.microsoft.azure</groupId> <artifactId>msal4j</artifactId> <version>1.13.3</version> </dependency>
实现代码
import com.microsoft.aad.msal4j.*; import java.util.Collections; import java.util.concurrent.CompletableFuture; public class SharePointOAuthAuth { public static void main(String[] args) throws Exception { String clientId = "your-azure-ad-client-id"; // 注册的Azure AD应用ID String username = "user@your-tenant.onmicrosoft.com"; String password = "your-password"; String tenantId = "your-tenant-id"; String sharePointResource = "https://your-tenant.sharepoint.com"; // SharePoint站点资源ID // 配置ROPC流参数 PublicClientApplication pca = PublicClientApplication.builder(clientId) .authority("https://login.microsoftonline.com/" + tenantId) .build(); UserNamePasswordParameters parameters = UserNamePasswordParameters.builder( Collections.singleton(sharePointResource + "/.default"), username, password.toCharArray()) .build(); // 获取AccessToken CompletableFuture<IAuthenticationResult> future = pca.acquireToken(parameters); IAuthenticationResult result = future.get(); String accessToken = result.accessToken(); // 使用Token请求SharePoint接口 try (CloseableHttpClient httpClient = HttpClients.createDefault()) { HttpGet request = new HttpGet("https://your-tenant.sharepoint.com/sites/your-site/_api/web/lists"); request.addHeader("Authorization", "Bearer " + accessToken); request.addHeader("Accept", "application/json;odata=verbose"); try (CloseableHttpResponse response = httpClient.execute(request)) { String responseBody = EntityUtils.toString(response.getEntity()); System.out.println(responseBody); } } } }
注意:ROPC流仅适用于无法使用交互式登录的场景,不推荐生产环境使用,且需在Azure AD应用中开启允许ROPC流的配置。
三、基于Access Token的直接身份验证
若已通过其他渠道获取有效SharePoint Access Token,直接在请求头中携带Authorization: Bearer <token>即可跳过登录页访问资源。
实现代码
import org.apache.http.client.methods.CloseableHttpResponse; import org.apache.http.client.methods.HttpGet; import org.apache.http.impl.client.CloseableHttpClient; import org.apache.http.impl.client.HttpClients; import org.apache.http.util.EntityUtils; public class SharePointTokenAuth { public static void main(String[] args) throws Exception { String sharePointUrl = "https://your-sharepoint-site.com/sites/your-site/_api/web/lists"; String accessToken = "your-valid-access-token"; try (CloseableHttpClient httpClient = HttpClients.createDefault()) { HttpGet request = new HttpGet(sharePointUrl); request.addHeader("Authorization", "Bearer " + accessToken); request.addHeader("Accept", "application/json;odata=verbose"); try (CloseableHttpResponse response = httpClient.execute(request)) { String responseBody = EntityUtils.toString(response.getEntity()); System.out.println(responseBody); } } } }
关键说明
- Token需具备访问目标SharePoint资源的权限,权限范围需包含
AllSites.Read、Sites.Read.All等对应权限; - Token有效期通常为1小时,过期后需重新获取或使用Refresh Token刷新。
内容的提问来源于stack exchange,提问作者mano
相关产品推荐
相关产品推荐

