如何从Office插件获取用户邮箱?解决SSO 13006认证错误
Office插件SSO认证13006错误排查与用户邮箱获取方案
一、13006错误的修复与排查
你的getToken函数存在异步逻辑缺陷:getAccessTokenAsync是异步方法,直接同步返回returnObject会导致返回值为undefined,这会触发后续认证流程异常,进而引发13006错误。
修复后的getToken函数需用Promise封装异步操作:
async getToken() { return new Promise((resolve, reject) => { window.Office.context.auth.getAccessTokenAsync( { allowConsentPrompt: true, allowSignInPrompt: true }, (result) => { console.log(result); if (result.status === "succeeded") { resolve(result.value); console.log(result.value); } else { console.log("Error obtaining token", result); reject(result.error); } } ); }); }
额外排查要点:
- 确认插件manifest.xml中已正确配置SSO权限,需包含
User.Read或Mail.Read等必要权限,且权限范围与Graph API调用需求匹配 - 检查Azure AD应用注册的重定向URI是否与插件部署域名完全一致(必须带https前缀)
- 确保使用的Office客户端版本支持SSO(要求Office 2016及以上版本或365订阅版,且已更新至最新补丁)
二、获取用户邮箱ID的方法
拿到有效token后,调用Graph API的/me端点获取用户信息,从中提取邮箱:
async getUserEmail() { const token = await this.getToken(); const response = await fetch("https://graph.microsoft.com/v1.0/me", { headers: { Authorization: `Bearer ${token}` } }); const userInfo = await response.json(); // 优先取mail字段,无则回退到userPrincipalName return userInfo.mail || userInfo.userPrincipalName; }
后续将获取到的邮箱替换到上传API路径中即可:
const userEmail = await getUserEmail(); const uploadUrl = `https://graph.microsoft.com/v1.0/users/${userEmail}/drive/items/root:/filename.docx:/content`; // 执行PUT上传操作
内容的提问来源于stack exchange,提问作者Prithavi raj
相关产品推荐
相关产品推荐

