You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非默认认证方案下,如何为DownstreamApi.CallApiForUserAsync指定认证方案?

非默认认证方案下,如何为DownstreamApi.CallApiForUserAsync指定认证方案?

这个问题的核心是:当你没有把OpenIdConnect设为默认认证方案时,DownstreamApi.CallApiForUserAsync 无法自动识别到你要使用Entra ID(原Azure AD)的身份凭证来调用下游API,它会默认 fallback 到Identity.Application方案,而这和你Controller中指定的OpenIdConnectDefaults.AuthenticationScheme不匹配,因此抛出了"无法确定云实例"的错误。

下面提供两种直接有效的解决方法:


方法一:在CallApiForUserAsync调用中显式指定认证方案

最直接的方式是在调用下游API时,通过重载方法传入authenticationScheme参数,明确告诉框架要用哪个认证方案的凭证:

修改你的Controller方法代码:

[Authorize(AuthenticationSchemes = OpenIdConnectDefaults.AuthenticationScheme)]
[AuthorizeForScopes(ScopeKeySection = "X:Scopes")]
public async Task<string> GetSomething()
{
    HttpResponseMessage response = await _downstreamApi.CallApiForUserAsync(
        "X", 
        authenticationScheme: OpenIdConnectDefaults.AuthenticationScheme, // 显式指定认证方案
        options =>
        {
            options.RelativePath = "path/Something";
        }); 
    // 后续处理逻辑...
}

这种方式的优势是精准控制单个接口的认证方案,适合不同接口可能使用不同认证方式的场景。


方法二:全局配置默认认证方案(一劳永逸)

如果你的应用中大部分下游API调用都需要用OpenIdConnect的凭证,可以在Startup的服务配置中,全局指定TokenAcquisition的默认认证方案:

修改你的Startup配置代码:

builder.Services.AddAuthentication()      
    .AddMicrosoftIdentityWebApp(builder.Configuration.GetSection("AzureAd"))
    .EnableTokenAcquisitionToCallDownstreamApi(         
        builder.Configuration.GetSection("X:Scopes").Get<string[]>(),
        options => 
        {
            // 全局指定TokenAcquisition使用的默认认证方案
            options.DefaultAuthenticationScheme = OpenIdConnectDefaults.AuthenticationScheme;
        }
    )
    .AddInMemoryTokenCaches()
    .AddDownstreamApi("X", builder.Configuration.GetSection("X"));

配置完成后,后续所有CallApiForUserAsync的调用都会自动使用这个指定的认证方案,不需要再逐个添加参数,适合统一使用同一认证方案的场景。


备注:内容来源于stack exchange,提问作者Greg

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.14 10:03:05