通过Postman调用Sharepoint REST API获取FedAuth Cookie的身份验证问题
适用场景
刚好匹配你当前无法完成应用注册、需要运行时通过账号密码获取认证凭据的需求,该流程无需预先注册应用,仅需要3次请求即可完成认证,不需要跟踪浏览器的8次重定向流程。
前置条件
- 你使用的账号未开启多因素认证(MFA),启用MFA的账号无法使用该方案
- 账号具备目标SharePoint站点的对应访问权限
- 提前确认你的SharePoint站点根地址,格式为
https://<租户前缀>.sharepoint.com
完整实现步骤
1. 向微软STS服务请求安全令牌
发送POST请求到地址https://login.microsoftonline.com/extSTS.srf,请求头指定Content-Type: application/xml,请求体为如下XML格式,替换其中的你的账号邮箱、你的账号密码、SharePoint站点根地址三个参数:
<s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://www.w3.org/2005/08/addressing" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" xmlns:wst="http://schemas.xmlsoap.org/ws/2005/02/trust"> <s:Header> <a:Action s:mustUnderstand="1">http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue</a:Action> <a:ReplyTo> <a:Address>http://www.w3.org/2005/08/addressing/anonymous</a:Address> </a:ReplyTo> <a:To s:mustUnderstand="1">https://login.microsoftonline.com/extSTS.srf</a:To> <wsse:Security s:mustUnderstand="1"> <wsse:UsernameToken> <wsse:Username>你的账号邮箱</wsse:Username> <wsse:Password>你的账号密码</wsse:Password> </wsse:UsernameToken> </wsse:Security> </s:Header> <s:Body> <wst:RequestSecurityToken> <wst:RequestType>http://schemas.xmlsoap.org/ws/2005/02/trust/Issue</wst:RequestType> <wsp:AppliesTo> <a:EndpointReference> <a:Address>SharePoint站点根地址</a:Address> </a:EndpointReference> </wsp:AppliesTo> <wst:KeyType>http://schemas.xmlsoap.org/ws/2005/05/identity/NoProofKey</wst:KeyType> </wst:RequestSecurityToken> </s:Body> </s:Envelope>
请求成功后,从返回的XML内容中提取wsse:BinarySecurityToken标签内的字符串,即为后续需要使用的安全令牌。
2. 兑换FedAuth与rtFa Cookie
发送POST请求到地址{你的SharePoint站点根地址}/_forms/default.aspx?wa=wsignin1.0,请求体为上一步提取到的安全令牌字符串,不需要额外请求头参数。
请求成功后,从响应头的Set-Cookie字段中提取FedAuth和rtFa两个Cookie值,两个Cookie需要同时使用才可以通过SharePoint的身份校验。
3. 调用SharePoint REST API
后续所有向SharePoint REST API发起的请求,只需在请求头中带上上述两个Cookie,即可完成身份验证,无需其他认证参数。
注意事项
- 如果你的租户启用了现代认证强制策略、或者账号属于联合身份托管,该方案可能失效
- FedAuth Cookie默认有效期为12小时,过期后需要重新执行上述流程获取新的Cookie
- 不要在生产环境硬编码账号密码,建议通过环境变量、加密配置等方式存储凭据
内容的提问来源于stack exchange,提问作者kierano
相关产品推荐
相关产品推荐

