使用MSAL和Spring后端OBO流程访问Microsoft Graph共享邮箱时,用户Consent界面不显示且令牌兑换抛出MsalInteractionRequiredException的问题求助
使用MSAL和Spring后端OBO流程访问Microsoft Graph共享邮箱时,用户Consent界面不显示且令牌兑换抛出MsalInteractionRequiredException的问题求助
我现在卡在一个使用MSAL(Microsoft Authentication Library)和Spring后端OBO(On-Behalf-Of)流程访问Microsoft Graph共享邮箱的问题上,想请教下各位怎么解决。
先给大家说明我的整体流程和配置:
- 我在Microsoft Entra管理中心注册了一个后端应用(简称BA)
- 给BA添加了
Mail.Read.Shared、Mail.ReadWrite.Shared这类Graph的委托权限 - 在BA的「暴露API」模块创建了自定义范围
api://<BA-client-ID>/outlook.offline.delegated.access,不过这里没有添加授权的客户端应用 - React前端通过MSAL触发用户授权,拿到委托令牌后传给BA,BA再用OBO流程将该令牌兑换为可访问Graph的访问令牌
前端React代码(获取委托令牌)
我特意设置了prompt: 'consent'来强制弹出用户授权界面,但实际测试时界面根本没出现,不过acquireTokenPopup倒是正常返回了令牌:
export const msalConfig: Configuration = { auth: { clientId: '<BA-client-ID>', authority: 'https://login.microsoftonline.com/common/', redirectUri: 'https://localhost:3000/redirect.html', navigateToLoginRequestUrl: false, }, cache: { cacheLocation: 'sessionStorage', storeAuthStateInCookie: false } }; export const loginRequest = { scopes: ["api://<BA-client-ID>/outlook.offline.delegated.access"], prompt: 'consent', // 我本以为这个参数会强制显示授权界面,但未生效 }; // ... 其他组件代码 const { instance, accounts } = useMsal(); const response = await instance.acquireTokenPopup({ ...loginRequest, }); const accessToken = response.accessToken;
后端Spring代码(OBO兑换Graph令牌)
前端把令牌传过来后,我用MSAL4J执行OBO兑换操作,结果直接抛出了异常:
OnBehalfOfParameters parameters = OnBehalfOfParameters .builder(Set.of("https://graph.microsoft.com/Mail.Read.Shared", "https://graph.microsoft.com/Mail.ReadWrite.Shared", "offline_access"), new UserAssertion(accessToken)) .build(); // 尝试兑换令牌 IAuthenticationResult result = confidentialClientApplication .acquireToken(parameters) .get();
抛出的异常信息:
com.microsoft.aad.msal4j.MsalInteractionRequiredException: AADSTS65001: The user or administrator has not consented to use the application with ID '
' named 'Spring Backend'. Send an interactive authorization request for this user and resource.
我已经尝试过的无效操作
- 清空浏览器的sessionStorage和所有Cookies后重新测试,问题依旧
- 把自定义范围
api://<BA-client-ID>/outlook.offline.delegated.access添加到BA的API权限列表中,没有任何改善
现在我有两个核心疑问:
- 明明设置了
prompt: 'consent',为什么用户授权界面还是不弹出? - 后端兑换令牌时抛出的AADSTS65001错误,到底是哪里配置缺失了?是不是暴露API时必须添加授权客户端?
麻烦大家帮忙排查下,谢谢啦!
内容来源于stack exchange
相关产品推荐
相关产品推荐

