如何从Azure token_id及adalService.userInfo获取memberId并验证用户组归属
Let's break down your two questions clearly to help you use the isMemberOf API effectively:
1. How to retrieve memberId from an Azure ID Token (token_id)
The memberId required for the isMemberOf API is the unique Object ID of the user, which is embedded directly in the Azure AD ID Token (a JWT-formatted token). Here's how to get it:
- Decode the ID Token: You can use a JWT parsing library in your code (like
jsonwebtokenfor Node.js orSystem.IdentityModel.Tokens.Jwtfor .NET) or a tool likejwt.iofor quick manual checks. - Once decoded, look for the
oidclaim in the token payload. Thisoidvalue is exactly thememberIdyou need to pass to the API.
Note: The
oidclaim is an immutable, unique identifier for the user in Azure AD, making it ideal for this membership verification scenario.
2. Which property in this.adalService.userInfo maps to memberId
After user authentication with ADAL, the userInfo object includes an objectId property that corresponds directly to the required memberId.
Your userInfo response will typically look something like this:
{ "username": "user@contoso.com", "profile": { "name": "John Doe", "objectId": "ea59e4d3-a7a1-4b5b-b65f-a25fcc0c0f99", // additional profile fields... }, // other userInfo properties... }
Simply extract the objectId value (either from this.adalService.userInfo.profile.objectId or directly from this.adalService.userInfo.objectId, depending on your ADAL implementation) and use it as the memberId in your isMemberOf API request body.
内容的提问来源于stack exchange,提问作者Raj4MS

