You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Microsoft Graph NuGet包V4.19+版本导致API调用挂起超时问题排查

Microsoft Graph API 4.19+版本调用SharePoint站点挂起超时问题

问题现象

使用Microsoft Graph API访问SharePoint站点时,NuGet包版本4.18及以下运行正常,但4.19及以上版本会导致API调用挂起,最终超时抛出"A task was canceled"错误。已排查代码死锁无问题,最小示例程序在执行GetSiteIdAsync获取Site Id步骤时挂起。代码如下:

internal async Task Initialize()
{
    await GetSpAccessTokenAsync();

    await GetSiteIdAsync();
}

private async Task GetSpAccessTokenAsync()
{
    try
    {
        Console.WriteLine("Get certificate.");
        X509Certificate2 certificate = GetCertificate(cfg.GraphCertificate, cfg.GraphPrivateKey, cfg.GraphPassphrase);
        if (certificate != null)
        {
            Console.WriteLine("Certificate obtained. Get access token.");
            AuthenticationResult authResult = await GetAccessTokenAsync(certificate);
            accessTokenExpiryDate = TimeZoneInfo.ConvertTimeFromUtc(authResult.ExpiresOn.UtcDateTime,
                                                                    TimeZoneInfo.FindSystemTimeZoneById("Central Standard Time"));
            Console.WriteLine($"Token expiry date: {accessTokenExpiryDate}");
            client = new GraphServiceClient(
                        new DelegateAuthenticationProvider(
                            (reqMsg) =>
                            {
                                // Append the access token to the request.
                                reqMsg.Headers.Authorization = new AuthenticationHeaderValue("bearer", authResult.AccessToken);
                                return Task.FromResult(0);
                            }));
        }
    }
    catch (Exception e)
    {
        Console.WriteLine($"Error in GetSpAccessTokenAsync(). {e.Message}");
        throw;
    }
}

private async Task<AuthenticationResult> GetAccessTokenAsync(X509Certificate2 certificate)
{
    string[] scopes = new string[] { "https://graph.microsoft.com/.default" };
    IConfidentialClientApplication app;
    app = ConfidentialClientApplicationBuilder.Create(cfg.GraphSpApplicationId)
                                              .WithAuthority(new Uri(cfg.CertificateAuthority))
                                              .WithCertificate(certificate)
                                              .Build();
    AuthenticationResult authenticationResult = await app.AcquireTokenForClient(scopes).ExecuteAsync();

    return authenticationResult;
}

private async Task GetSiteIdAsync()
{
    try
    {
        Console.WriteLine("Get site id.");
        Site site = await client.Sites
                                .GetByPath(cfg.SharePointSiteUrl.AbsolutePath, cfg.SharePointSiteUrl.DnsSafeHost)
                                .Request()
                                .GetAsync();
        Console.WriteLine("Site API invoked.");
        siteId = site.Id;
        Console.WriteLine($"Site id = {siteId}");
    }
    catch (Exception e)
    {
        Console.WriteLine($"Exception in GetSiteIdAsync(). {e.Message}");
    }
}

补充环境信息:3台服务器中2台出现该问题,1台可正常运行,正协调部署Wireshark抓包,现寻求前置排查思路。

排查思路

  • 检查.NET版本与依赖兼容性:对比故障/正常服务器的.NET运行时版本,以及System.Net.Http、Microsoft.Identity.Client等依赖库版本,确认是否存在版本过低或冲突。
  • 验证TLS配置差异:Graph SDK 4.19+可能默认启用更高版本TLS(如TLS 1.3),检查故障服务器是否启用TLS 1.2/1.3,对比注册表中HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols下的TLS配置项。
  • 排查代理与网络策略:确认故障服务器的代理配置(环境变量、应用内设置)是否与正常服务器一致;检查防火墙/安全组是否拦截Graph API请求;用curl或Invoke-WebRequest测试服务器到https://graph.microsoft.com的基础连通性。
  • 证书与身份验证日志:检查故障服务器证书的存储位置、私钥读取权限;在MSAL初始化时添加日志,查看身份验证过程是否有隐藏异常:
    app = ConfidentialClientApplicationBuilder.Create(cfg.GraphSpApplicationId)
        .WithAuthority(new Uri(cfg.CertificateAuthority))
        .WithCertificate(certificate)
        .WithLogging((level, message, containsPii) =>
        {
            Console.WriteLine($"MSAL Log: {level} - {message}");
        }, LogLevel.Verbose)
        .Build();
    
  • 自定义HTTP客户端配置:Graph SDK 4.19+可能修改了默认HTTP客户端设置,尝试手动创建HttpClient并传入GraphServiceClient,覆盖超时、连接池等配置:
    var httpClient = new HttpClient(new HttpClientHandler())
    {
        Timeout = TimeSpan.FromMinutes(5)
    };
    client = new GraphServiceClient(httpClient, new DelegateAuthenticationProvider(...));
    
  • 系统资源与事件日志:检查故障服务器的CPU、内存、带宽使用率,确认是否资源耗尽;查看系统事件日志,排查网络、进程相关异常记录。

内容的提问来源于stack exchange,提问作者gs_rider

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 18:18:50