如何限制Azure Linux VM仅允许SharePoint Online认证用户的AJAX请求访问?
Absolutely, there are several secure, practical ways to ensure your Azure Linux VM-hosted API only accepts AJAX requests from authenticated SharePoint Online users. Let’s dive into the most effective approaches, tailored to your Microsoft 365 ecosystem:
1. Azure AD OAuth 2.0 Authentication (Recommended)
This is the most robust method since it leverages Microsoft’s native identity system, ensuring you’re verifying individual user identities directly. Here’s how to set it up:
- Register your API in Azure AD: Create an app registration for your API, define a unique
Application ID URI(this becomes the token audience), and configure it to accept tokens from your SharePoint tenant. - Fetch user tokens in SharePoint: Use SharePoint Framework (SPFx) or plain JavaScript to retrieve the current user’s Azure AD access token. For example, in SPFx, you can use the
@microsoft/sp-httplibrary to get a token targeted at your API’s audience. - Pass tokens in AJAX requests: Include the token in the
Authorizationheader of your AJAX calls:$.ajax({ url: "https://your-azure-vm-api-url.com/endpoint", headers: { "Authorization": "Bearer " + userAccessToken }, method: "GET", success: function(data) { /* handle response */ } }); - Validate tokens on your Linux API: Use a library compatible with your tech stack to verify the token. For Node.js APIs,
passport-azure-adworks great; for Python, usemsal. Ensure you check:- The token’s
aud(audience) matches your API’s Azure AD client ID - The token’s
iss(issuer) is your tenant’s Azure AD endpoint - The token isn’t expired and has valid signatures
- The token’s
2. Azure Front Door + IP Restriction + Azure AD Auth
If you want an extra layer of network security, wrap your VM API behind Azure Front Door:
- Configure Front Door for Azure AD auth: Enable Azure AD authentication on Front Door so only logged-in users can pass through.
- Restrict Front Door to SharePoint IPs: Limit Front Door’s incoming traffic to Microsoft’s published SharePoint Online IP ranges (you can find these in the Microsoft 365 Admin Center).
- Lock down VM to Front Door IPs: Update your VM’s network security group (NSG) to only allow traffic from Front Door’s public IP addresses.
- Bonus: Front Door handles CORS for you, so you can easily restrict allowed origins to your SharePoint site.
3. SharePoint App-Only Permissions (User-agnostic alternative)
If you don’t need to verify individual users but just want to ensure requests come from your SharePoint site, use app-only permissions:
- Register a SharePoint Add-in: Create an app in SharePoint, grant it the necessary permissions, and get a client ID/secret.
- Generate app-only tokens: In your SharePoint page, generate an app-only token using the client ID/secret, and pass it in your AJAX request headers.
- Validate tokens on your API: Verify the token’s signature and ensure it’s issued for your SharePoint tenant. Note: This method doesn’t distinguish between users—it only confirms the request is from your authorized SharePoint app.
Critical CORS Configuration
Since your SharePoint site and Azure VM are cross-domain, you must configure CORS on your Linux VM to only allow your SharePoint domain. For example, if using Nginx as a reverse proxy:
location /your-api-path { add_header Access-Control-Allow-Origin "https://your-sharepoint-site.sharepoint.com"; add_header Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"; add_header Access-Control-Allow-Headers "Authorization, Content-Type"; if ($request_method = OPTIONS) { return 204; } proxy_pass http://localhost:your-api-port; }
This ensures browsers only allow AJAX requests from your SharePoint site to your API.
内容的提问来源于stack exchange,提问作者Frank

