使用EWS读取邮件时触发MSAL invalid_client错误(AADSTS7000218)的问题求助
大家好,我最近在尝试用EWS结合MSAL实现Office365邮件的读取功能,结果碰到了一个认证错误,折腾了很久都没解决,来请教下各位!
错误信息
当我运行代码时,直接抛出了MSAL的服务异常,具体错误如下:
Error acquiring access token: MSAL.NetCore.4.72.1.0.MsalServiceException: ErrorCode: invalid_client
Microsoft.Identity.Client.MsalServiceException: A configuration issue is preventing authentication - check the error message from the server for details. You can modify the configuration in the application registration portal.
Original exception: AADSTS7000218: The request body must contain the following parameter: 'client_assertion' or 'client_secret'.
背景说明
我已经参考了官方的EWS OAuth认证思路来写代码,用的是Microsoft.Identity.Client(版本4.22.0)的PublicClientApplication做交互式登录——我理解这种模式是面向用户的交互式授权,不需要客户端密钥,但错误却要求提供client_secret或者client_assertion,这让我有点摸不着头脑。
我的代码
using Microsoft.Exchange.WebServices.Data; using Microsoft.Identity.Client; using System; using System.Configuration; namespace EwsOAuth { internal class Program { private static async System.Threading.Tasks.Task Main(string[] args) { // Using Microsoft.Identity.Client 4.22.0 // Configure the MSAL client to get tokens var pcaOptions = new PublicClientApplicationOptions { ClientId = ConfigurationManager.AppSettings["appId"], TenantId = ConfigurationManager.AppSettings["tenantId"] }; var pca = PublicClientApplicationBuilder .CreateWithApplicationOptions(pcaOptions) .WithRedirectUri("http://localhost") .Build(); // The permission scope required for EWS access var ewsScopes = new string[] { "https://outlook.office365.com/EWS.AccessAsUser.All" }; try { // Make the interactive token request var authResult = await pca .AcquireTokenInteractive(ewsScopes) .WithEmbeddedWebViewOptions(new EmbeddedWebViewOptions()) .ExecuteAsync(); // Configure the ExchangeService with the access token var ewsClient = new ExchangeService(); ewsClient.Url = new Uri("https://outlook.office365.com/EWS/Exchange.asmx"); ewsClient.Credentials = new OAuthCredentials(authResult.AccessToken); // Make an EWS call var folders = ewsClient.FindFolders(WellKnownFolderName.MsgFolderRoot, new FolderView(10)); foreach (var folder in folders) { Console.WriteLine($"Folder: {folder.DisplayName}"); } } catch (MsalException ex) { Console.WriteLine($"Error acquiring access token: {ex}"); } catch (Exception ex) { Console.WriteLine($"Error: {ex}"); } if (System.Diagnostics.Debugger.IsAttached) { Console.WriteLine("Hit any key to exit..."); Console.ReadKey(); } } } }
我的疑问
- 为什么使用交互式登录的Public Client会被要求提供
client_secret?这和我对Public Client模式的理解不符啊 - 是我在Azure AD应用注册里的配置哪里错了吗?还是代码里的MSAL客户端构建有遗漏的参数?
希望有经验的朋友能帮我排查下问题,谢谢啦!
内容来源于stack exchange

