Azure CLI设置Azure DevOps Readers组权限遇Token问题求助
Azure DevOps通过Azure CLI配置Readers组权限的Token问题
需求目标
为Azure DevOps中的Readers组自动化配置两项权限:
- 删除团队项目
- 编辑项目级信息
当前配置代码(PowerShell+Azure CLI)
$OrgName = "" $ProName = "" Write-Host "Project Name is " $ProName -ForegroundColor Green # 获取Namespace ID $namespaceId = az devops security permission namespace list --org "https://dev.azure.com/$OrgName/" --query "[?@.name == 'Project'].namespaceId | [0]" -o tsv Write-Host "Name Space Id is " $namespaceId # 获取Readers组的descriptor $GroupName = "Readers" Write-Host "Group Name is " $GroupName $Subject = az devops security group list --org https://dev.azure.com/$OrgName/ --project $ProName --query "graphGroups[?displayName == '$GroupName'].descriptor | [0]" -o tsv Write-Host "Subject is " $Subject # 获取编辑项目信息对应的权限bit值(GENERIC_WRITE) $writeBit = az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/" --query "[0].actions[?@.name == 'GENERIC_WRITE'].bit |[0]" -o tsv Write-Host "GENERIC_WRITE Bit is " $writeBit # 获取删除项目对应的权限bit值(GENERIC_DELETE) $deleteBit = az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/" --query "[0].actions[?@.name == 'GENERIC_DELETE'].bit |[0]" -o tsv Write-Host "GENERIC_DELETE Bit is " $deleteBit # 获取项目ID $ProjID = az devops project list --org https://dev.azure.com/$OrgName/ --query "value[?name == '$ProName'].id |[0]" -o tsv Write-Host "Project ID is " $ProjID # 配置编辑项目信息权限 az devops security permission update --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --allow-bit $writeBit --merge true --org "https://dev.azure.com/$OrgName/" -o table # 配置删除项目权限 az devops security permission update --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --allow-bit $deleteBit --merge true --org "https://dev.azure.com/$OrgName/" -o table # 查看权限条目 az devops security permission show --id $namespaceId --subject $Subject --token "vstfs:///Classification/TeamProject/$ProjID" --org "https://dev.azure.com/$OrgName/" -o table # 查看该命名空间下所有权限选项及bit值 az devops security permission namespace show --namespace-id $namespaceId --org "https://dev.azure.com/$OrgName/"
遇到的问题
- 使用无效随机数字作为Token时,命令能正常执行并返回权限已添加,但实际无任何权限生效
- 按照文档拼接
$PROJECT:vstfs:///Classification/TeamProject/$ProjID格式的Token时,会生成无效的新Token条目,ADO门户权限页面无变化 - 当前权限列表输出:
Token Effective Allow Effective Deny --------------------------------------------------------------------------------- ----------------- ---------------- $PROJECT:vstfs:///Classification/TeamProject/e648b2f1-b6c8-4c73-8024-xxxxxxxxxxxx 0 0 $PROJECT:vstfs:///Classification/TeamProject/ede8562f-3c53-4af7-8b2f-xxxxxxxxxxxx 0 0 $PROJECT:vstfs:///Classification/TeamProject/f11081f7-a109-4969-8ac2-xxxxxxxxxxxx 0 0 $PROJECT:vstfs:///Classification/TeamProject/f31ed069-717a-4dae-88c5-xxxxxxxxxxxx 0 0 $PROJECT:vstfs:///Classification/TeamProject/fb881522-23c6-41be-847c-xxxxxxxxxxxx 0 0 ///Classification/TeamProject/78558778 0 0 ///Classification/TeamProject/910e9e11-81ea-471b-8ed3-xxxxxxxxxxxx 0 0 ///Classification/TeamProject/*******shop 0 0 ///Classification/TeamProject/e38e6183-e385-4605-96be-xxxxxxxxxxxx 2 0
问题解决要点
- 正确的Token格式:Project命名空间的有效Token不需要
$PROJECT:前缀,直接使用vstfs:///Classification/TeamProject/{ProjectID}即可,从权限列表最后一行的有效条目可以验证这一点(其Effective Allow为2,对应GENERIC_WRITE的bit值) - 修正变量大小写:PowerShell区分大小写,确保代码中
$Subject变量的大小写一致,避免因变量未正确赋值导致权限配置失效 - 获取正确的权限bit值:
- 编辑项目级信息对应
GENERIC_WRITE,bit值为2 - 删除团队项目对应
GENERIC_DELETE,bit值为4 - 使用
-o tsv参数获取纯bit值,避免az cli返回的字符串带引号导致配置错误
- 编辑项目级信息对应
- 合并权限配置:使用
--merge true参数确保新配置的权限与已有权限合并,而非覆盖
内容的提问来源于stack exchange,提问作者Vishal Thakur
相关产品推荐
相关产品推荐

