You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

On-prem TFS 2017u2是否存在获取当前用户身份信息的REST API?

Getting Current User Identity Details in On-Prem TFS 2017 Update 2 via REST API

Great question! It’s true that Azure DevOps Services (formerly VSTS) has a much richer set of profile-related APIs, but on-prem TFS 2017 Update 2 does offer a few endpoints to retrieve key identity details for the authenticated user. Here’s what you can use:

1. Basic User Identity Information

The primary endpoint to get core details about the current user is:

GET https://<your-tfs-server>/<collection>/_apis/identity/me?api-version=2.0

This returns essential fields like:

  • id: The unique GUID for the user
  • displayName: Full name of the user
  • uniqueName: The user's login name (e.g., domain\username or email)
  • descriptor: The identity descriptor used in other security-related APIs

2. User Group Memberships

To get the groups the current user belongs to, use the memberships endpoint:

GET https://<your-tfs-server>/<collection>/_apis/identity/me/memberships?api-version=2.0

This returns a list of groups, including each group’s id, displayName, and descriptor. Note that this includes both TFS-native groups and Active Directory groups synced to TFS.

3. Permission Checks

There’s no single endpoint that returns all permissions for the current user, but you can evaluate permissions for specific resources using the permission evaluation API. For example, to check permissions on a specific project:

POST https://<your-tfs-server>/<collection>/_apis/security/permissionevaluations?api-version=2.0
Content-Type: application/json

{
  "securityNamespaceId": "5a27515b-ccd7-42c9-84f1-54c998f03866", // Project namespace ID
  "token": "vstfs:///Classification/TeamProject/<project-id>",
  "descriptors": ["<user-descriptor-from-me-endpoint>"],
  "permissions": 32 // Example permission bit (e.g., View project-level information)
}

You’ll need to reference the appropriate security namespace IDs and permission bits for the resource you’re checking—these are documented in TFS’s REST API reference.

4. OAuth Scopes (If Using OAuth Authentication)

TFS 2017 Update 2 doesn’t have a dedicated API to retrieve OAuth scopes for the current token, but you can:

  • Parse the JWT token directly (if your client has access to it) to extract the scp claim, which lists the granted scopes.
  • When requesting the OAuth token initially, the response includes the scope field with the list of approved scopes—you can store this value for later use.

Key Note vs. VSTS/Azure DevOps Services

As you noticed, VSTS offers endpoints like /_apis/profile/profiles/me that return extended profile data (like contact info, preferences, etc.). These endpoints are not available in on-prem TFS 2017 Update 2—you’ll have to rely on the identity-focused endpoints listed above.

内容的提问来源于stack exchange,提问作者Seva Alekseyev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:34:20