You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure AD多WebApi端点场景下Bearer Token的扩展使用咨询

Extending Azure AD Implicit Flow to Multiple Web APIs

Great question! I’ve worked through this exact scenario when scaling Angular/.NET Web API apps with Azure AD, so let’s break down the practical, actionable approaches you can use.

The older v1.0 endpoint relies on a single resource parameter, but the v2.0 endpoint uses scopes to request access to multiple APIs in one authorization call. Here’s how to set this up:

  • Register each Web API in Azure AD: For every new Web API (e.g., App2 API), create a separate app registration. Define custom scopes like access_as_user or use the default ones provided.
  • Request multiple scopes from your Angular app: Replace the resource parameter with a space-separated list of scopes for all APIs you need access to. Example authorization request:
    https://login.microsoftonline.com/{tenant-id}/oauth2/v2.0/authorize?
    client_id={angular-app-id}
    &response_type=id_token token
    &redirect_uri={your-redirect-uri}
    &scope=api://{api1-app-id}/access_as_user api://{api2-app-id}/access_as_user openid profile
    &response_mode=fragment
    
  • Validate tokens in each Web API: Each .NET Web API should validate its specific scope in the token’s scp claim, plus the issuer and your Angular app’s client ID (from the azp claim). In your Startup.cs:
    services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
        .AddJwtBearer(options =>
        {
            options.Authority = "https://login.microsoftonline.com/{tenant-id}/v2.0";
            options.Audience = "api://{api2-app-id}";
            options.TokenValidationParameters = new TokenValidationParameters
            {
                ValidateIssuer = true,
                ValidIssuer = "https://login.microsoftonline.com/{tenant-id}/v2.0",
                ValidateAudience = true,
                ValidAudience = "api://{api2-app-id}",
                ValidateLifetime = true,
                RoleClaimType = "roles",
                NameClaimType = "name"
            };
        });
    

Option 2: Request Separate Tokens for Each API (v1.0 or v2.0)

If you need to stick with the v1.0 endpoint and resource parameter, you can initiate separate authorization requests for each Web API:

  • First token for API 1: Keep your existing flow as-is, requesting resource={api1-app-id} to get a token valid for API 1.
  • Second token for API 2: When your Angular app needs to call API 2, trigger another implicit flow request with resource={api2-app-id}. Since the user is already authenticated, Azure AD will return the second token without re-prompting for login (you can use a hidden iframe for silent authentication).
  • Manage tokens in Angular: Use a token storage service to map each token to its corresponding API endpoint. Libraries like MSAL Angular handle this automatically if you configure a protectedResourceMap that links API URLs to their resources/scopes.

Option 3: Incremental Authorization (For Progressive Access)

If your app doesn’t need access to all APIs upfront, use incremental authorization to request additional permissions later:

  • Initial login: Only request scopes for API 1.
  • When needing API 2: Trigger a new authorization request with API 2’s scopes. Azure AD will prompt the user to consent to the new permissions (if not already granted) and return a new token that includes both sets of scopes.
  • Update token storage: Replace or supplement your existing token with the new one that covers both APIs.

Key Notes to Keep in Mind

  • Consent Management: Ensure your Angular app has been granted delegated permissions to all Web APIs in Azure AD (via the "API permissions" tab in your Angular app’s registration).
  • Token Security: Since implicit flow exposes tokens in the browser, store them securely—use HttpOnly cookies if possible, or secure session storage with proper security headers like Content-Security-Policy.
  • MSAL Angular Simplifies This: If you’re using the MSAL Angular library, most of this work is handled for you. Just configure the protectedResourceMap in your module setup to map each API endpoint to its respective scopes/resources.

内容的提问来源于stack exchange,提问作者cobolstinks

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:46:43