You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求协助解决SharePoint OAuth 2.0令牌问题及获取刷新令牌

解决SharePoint API调用的AudienceUriValidationFailedException错误
  • 问题本质:你的Access Token的aud(受众)字段与SharePoint API预期的受众不匹配。SharePoint Online的受众格式通常是https://<你的租户>.sharepoint.com,或租户ID关联格式00000003-0000-0ff1-ce00-000000000000/<你的租户>.sharepoint.com@<租户ID>。
  • 排查与修复:
    1. 本地解码Access Token(用JWT解码工具,避免在线工具泄露信息),查看aud字段值。
    2. 确认SharePoint API请求地址与aud完全匹配:比如aud是https://contoso.sharepoint.com,API请求必须是该域名下的接口(如https://contoso.sharepoint.com/_api/web),不能使用租户my站点或其他子域。
    3. 检查Azure AD应用的权限范围:申请SharePoint权限时,要指定对应站点的范围(如https://contoso.sharepoint.com/.default),而非Microsoft Graph的全局范围。
    4. 获取Token时指定正确参数:
      • 应用权限(客户端凭证流):scope设为https://<你的租户>.sharepoint.com/.default;
      • 委派权限:scope设为具体权限(如https://<你的租户>.sharepoint.com/AllSites.Read)。
      • 若使用旧版Token端点,需确保resource参数为你的SharePoint站点根地址(如https://contoso.sharepoint.com)。
获取SharePoint Refresh Token的方法

只有委派权限流(Authorization Code Flow、Authorization Code Flow with PKCE)能获取Refresh Token,客户端凭证流无Refresh Token。

核心步骤(Node.js实现示例)

1. 获取授权码

引导用户访问授权端点,需包含offline_access scope(否则不会返回Refresh Token):

const tenantId = '你的租户ID';
const clientId = '你的应用客户端ID';
const redirectUri = '你的重定向URI';
const authUrl = `https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/authorize?client_id=${clientId}&response_type=code&redirect_uri=${redirectUri}&response_mode=query&scope=https://<你的租户>.sharepoint.com/AllSites.Read offline_access&state=12345`;
// 跳转至该URL,用户授权后会携带code参数返回至redirectUri

2. 用授权码交换Token(含Refresh Token)

const axios = require('axios');

async function getTokens(authorizationCode) {
  const tokenResponse = await axios.post(
    `https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/token`,
    new URLSearchParams({
      client_id: clientId,
      client_secret: '你的应用客户端密钥',
      code: authorizationCode,
      redirect_uri: redirectUri,
      grant_type: 'authorization_code',
      scope: 'https://<你的租户>.sharepoint.com/AllSites.Read offline_access'
    })
  );
  // tokenResponse.data包含access_token、refresh_token等字段
  return tokenResponse.data;
}

3. 用Refresh Token刷新Access Token

async function refreshAccessToken(refreshToken) {
  const refreshResponse = await axios.post(
    `https://login.microsoftonline.com/${tenantId}/oauth2/v2.0/token`,
    new URLSearchParams({
      client_id: clientId,
      client_secret: '你的应用客户端密钥',
      refresh_token: refreshToken,
      grant_type: 'refresh_token',
      scope: 'https://<你的租户>.sharepoint.com/AllSites.Read offline_access'
    })
  );
  // 保存返回的新refresh_token(旧的会失效)
  return refreshResponse.data;
}
  • 注意事项:
    • Refresh Token默认90天过期,每次使用后旧Token失效,需保存新返回的refresh_token。
    • Azure AD应用中必须配置与请求一致的重定向URI。

内容的提问来源于stack exchange,提问作者amit vcrew

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 22:36:32