使用Microsoft Graph更新来宾用户头像遇ErrorInsufficientPermissionsInAccessToken错误
问题:无法通过Microsoft Graph更新来宾用户头像
问题现象
- 尝试更新来宾用户个人头像时,Postman及自研前端均触发权限异常;但GET请求可正常获取该来宾用户头像,支持的路径包括
users/{userid}/photo/$value和me/photo/$value。 - 无论使用PUT还是PATCH请求,在
/beta/和/v1.0/版本的对应路径下均无法完成更新。 - 非来宾用户的头像可正常修改,仅来宾用户出现此问题。
错误信息
Code: ErrorInsufficientPermissionsInAccessToken
Message: Exception of type 'Microsoft.Fast.Profile.Core.Exception.ProfileAccessDeniedException' was thrown.
Inner error:
AdditionalData:
已配置的权限范围
请求携带的scp权限列表如下:
AllSites.Read Calendars.Read Calendars.ReadWrite Calendars.ReadWrite.Shared Contacts.Read Directory.AccessAsUser.All EWS.AccessAsUser.All Files.Read.All Group.Read.All Group.ReadWrite.All Mail.Read Mail.Send MailboxSettings.Read MyFiles.Read Notes.Read Notifications.ReadWrite.CreatedByApp openid People.Read People.Read.All Place.Read.All Presence.Read.All profile Sites.Read.All Sites.Search.All Tasks.ReadWrite TermStore.Read.All User.Read User.Read.All User.ReadWrite UserActivity.ReadWrite.CreatedByApp UserNotification.ReadWrite.CreatedByApp
已包含文档要求的User.ReadWrite权限。
请求代码示例
使用Microsoft Graph SDK发起PUT请求的代码:
var photoBytes = Convert.FromBase64String(photoData); var stream = new MemoryStream(photoBytes); var graphServiceClient = new GraphProvider(graphToken).GraphServiceClient; return graphServiceClient.Users[userId].Photo.Content .Request() .PutAsync(stream);
注:尝试过使用用户ID和用户主体名称两种方式发起请求,均触发相同异常。
疑问
这是Microsoft Graph本身的限制,还是我遗漏了某些必要的配置?
内容的提问来源于stack exchange,提问作者Wolly
相关产品推荐
相关产品推荐

