You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用MSAL和Spring后端OBO流程访问Microsoft Graph共享邮箱时,用户Consent界面不显示且令牌兑换抛出MsalInteractionRequiredException的问题求助

使用MSAL和Spring后端OBO流程访问Microsoft Graph共享邮箱时,用户Consent界面不显示且令牌兑换抛出MsalInteractionRequiredException的问题求助

我现在卡在一个使用MSAL(Microsoft Authentication Library)和Spring后端OBO(On-Behalf-Of)流程访问Microsoft Graph共享邮箱的问题上,想请教下各位怎么解决。

先给大家说明我的整体流程和配置:

  • 我在Microsoft Entra管理中心注册了一个后端应用(简称BA)
  • 给BA添加了Mail.Read.Shared、Mail.ReadWrite.Shared这类Graph的委托权限
  • 在BA的「暴露API」模块创建了自定义范围api://<BA-client-ID>/outlook.offline.delegated.access,不过这里没有添加授权的客户端应用
  • React前端通过MSAL触发用户授权,拿到委托令牌后传给BA,BA再用OBO流程将该令牌兑换为可访问Graph的访问令牌

前端React代码(获取委托令牌)

我特意设置了prompt: 'consent'来强制弹出用户授权界面,但实际测试时界面根本没出现,不过acquireTokenPopup倒是正常返回了令牌:

export const msalConfig: Configuration = {
  auth: {
    clientId: '<BA-client-ID>',
    authority: 'https://login.microsoftonline.com/common/',
    redirectUri: 'https://localhost:3000/redirect.html',
    navigateToLoginRequestUrl: false,
  },
  cache: {
    cacheLocation: 'sessionStorage',
    storeAuthStateInCookie: false
  }
};

export const loginRequest = {
  scopes: ["api://<BA-client-ID>/outlook.offline.delegated.access"],
  prompt: 'consent', // 我本以为这个参数会强制显示授权界面,但未生效
};

// ... 其他组件代码

const { instance, accounts } = useMsal();
const response = await instance.acquireTokenPopup({ ...loginRequest, });
const accessToken = response.accessToken;

后端Spring代码(OBO兑换Graph令牌)

前端把令牌传过来后,我用MSAL4J执行OBO兑换操作,结果直接抛出了异常:

OnBehalfOfParameters parameters = OnBehalfOfParameters
    .builder(Set.of("https://graph.microsoft.com/Mail.Read.Shared", 
                     "https://graph.microsoft.com/Mail.ReadWrite.Shared", 
                     "offline_access"), 
             new UserAssertion(accessToken))
    .build();

// 尝试兑换令牌
IAuthenticationResult result = confidentialClientApplication
    .acquireToken(parameters)
    .get();

抛出的异常信息:

com.microsoft.aad.msal4j.MsalInteractionRequiredException: AADSTS65001: The user or administrator has not consented to use the application with ID '' named 'Spring Backend'. Send an interactive authorization request for this user and resource.

我已经尝试过的无效操作

  • 清空浏览器的sessionStorage和所有Cookies后重新测试,问题依旧
  • 把自定义范围api://<BA-client-ID>/outlook.offline.delegated.access添加到BA的API权限列表中,没有任何改善

现在我有两个核心疑问:

  1. 明明设置了prompt: 'consent',为什么用户授权界面还是不弹出?
  2. 后端兑换令牌时抛出的AADSTS65001错误,到底是哪里配置缺失了?是不是暴露API时必须添加授权客户端?

麻烦大家帮忙排查下,谢谢啦!

内容来源于stack exchange

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.08 14:23:53