You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Postman调用Sharepoint REST API获取FedAuth Cookie的身份验证问题

适用场景

刚好匹配你当前无法完成应用注册、需要运行时通过账号密码获取认证凭据的需求,该流程无需预先注册应用,仅需要3次请求即可完成认证,不需要跟踪浏览器的8次重定向流程。

前置条件

  • 你使用的账号未开启多因素认证(MFA),启用MFA的账号无法使用该方案
  • 账号具备目标SharePoint站点的对应访问权限
  • 提前确认你的SharePoint站点根地址,格式为https://<租户前缀>.sharepoint.com

完整实现步骤

1. 向微软STS服务请求安全令牌

发送POST请求到地址https://login.microsoftonline.com/extSTS.srf,请求头指定Content-Type: application/xml,请求体为如下XML格式,替换其中的你的账号邮箱、你的账号密码、SharePoint站点根地址三个参数:

<s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://www.w3.org/2005/08/addressing" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" xmlns:wst="http://schemas.xmlsoap.org/ws/2005/02/trust">
  <s:Header>
    <a:Action s:mustUnderstand="1">http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue</a:Action>
    <a:ReplyTo>
      <a:Address>http://www.w3.org/2005/08/addressing/anonymous</a:Address>
    </a:ReplyTo>
    <a:To s:mustUnderstand="1">https://login.microsoftonline.com/extSTS.srf</a:To>
    <wsse:Security s:mustUnderstand="1">
      <wsse:UsernameToken>
        <wsse:Username>你的账号邮箱</wsse:Username>
        <wsse:Password>你的账号密码</wsse:Password>
      </wsse:UsernameToken>
    </wsse:Security>
  </s:Header>
  <s:Body>
    <wst:RequestSecurityToken>
      <wst:RequestType>http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</wst:RequestType>
      <wsp:AppliesTo>
        <a:EndpointReference>
          <a:Address>SharePoint站点根地址</a:Address>
        </a:EndpointReference>
      </wsp:AppliesTo>
      <wst:KeyType>http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</wst:KeyType>
    </wst:RequestSecurityToken>
  </s:Body>
</s:Envelope>

请求成功后,从返回的XML内容中提取wsse:BinarySecurityToken标签内的字符串,即为后续需要使用的安全令牌。

发送POST请求到地址{你的SharePoint站点根地址}/_forms/default.aspx?wa=wsignin1.0,请求体为上一步提取到的安全令牌字符串,不需要额外请求头参数。
请求成功后,从响应头的Set-Cookie字段中提取FedAuth和rtFa两个Cookie值,两个Cookie需要同时使用才可以通过SharePoint的身份校验。

3. 调用SharePoint REST API

后续所有向SharePoint REST API发起的请求,只需在请求头中带上上述两个Cookie,即可完成身份验证,无需其他认证参数。

注意事项

  • 如果你的租户启用了现代认证强制策略、或者账号属于联合身份托管,该方案可能失效
  • FedAuth Cookie默认有效期为12小时,过期后需要重新执行上述流程获取新的Cookie
  • 不要在生产环境硬编码账号密码,建议通过环境变量、加密配置等方式存储凭据

内容的提问来源于stack exchange,提问作者kierano

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.27 12:09:00