You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

请求Azure AD访问令牌时如何添加resource额外参数

解决Azure AD OAuth2请求缺少resource参数导致的AADSTS50001错误

你遇到的AADSTS50001错误是因为Azure AD的旧版OAuth2令牌端点(/oauth2/token)必须指定resource参数——这个参数用来标识你要访问的目标资源(比如某个API的应用ID URI),但Swashbuckle.AspNetCore默认的OAuth2流程不会自动添加这个参数。下面给你几个可行的解决办法:

方法1:自定义请求拦截器(推荐,灵活可控)

通过实现Swashbuckle的IOAuth2RequestInterceptor接口,在令牌请求发送前自动注入resource参数:

首先创建拦截器类:

using Swashbuckle.AspNetCore.SwaggerGen;
using System.Collections.Generic;

public class AzureAdResourceInterceptor : IOAuth2RequestInterceptor
{
    private readonly string _targetResourceId;

    public AzureAdResourceInterceptor(string resourceId)
    {
        _targetResourceId = resourceId;
    }

    public void InterceptTokenRequest(IDictionary<string, string> requestData)
    {
        // 确保只添加一次resource参数
        if (!requestData.ContainsKey("resource"))
        {
            requestData.Add("resource", _targetResourceId);
        }
    }
}

然后在你的Swagger配置中注册这个拦截器,并关联到OAuth2安全定义:

// 从配置文件读取目标资源的ID(比如你要访问的API的应用ID URI)
var targetResourceId = _configuration["Auth:Resource:Id"];

c.AddSecurityDefinition("oauth2", new OAuth2Scheme
{
    Type = "oauth2",
    Flow = "accessCode",
    AuthorizationUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/authorize",
    TokenUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/token",
});

// 注册自定义拦截器,自动为令牌请求添加resource参数
c.AddOAuth2RequestInterceptor(new AzureAdResourceInterceptor(targetResourceId));

方法2:直接在URL中拼接参数(简单但不够灵活)

如果你的资源ID固定不变,可以直接把resource参数拼接到授权和令牌请求的URL中:

var targetResourceId = _configuration["Auth:Resource:Id"];

c.AddSecurityDefinition("oauth2", new OAuth2Scheme
{
    Type = "oauth2",
    Flow = "accessCode",
    AuthorizationUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/authorize?resource={targetResourceId}",
    TokenUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/token?resource={targetResourceId}",
});

额外建议:切换到Azure AD v2.0端点(微软推荐)

如果你的应用支持,建议改用Azure AD的v2.0端点,它使用标准OAuth2的scope参数代替resource,更符合现代OAuth2规范:

var targetResourceId = _configuration["Auth:Resource:Id"];

c.AddSecurityDefinition("oauth2", new OAuth2Scheme
{
    Type = "oauth2",
    Flow = "accessCode",
    AuthorizationUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/v2.0/authorize",
    TokenUrl = $"https://login.microsoftonline.com/{_configuration["Auth:Tanent:TanentId"]}/oauth2/v2.0/token",
    Scopes = new Dictionary<string, string>
    {
        { $"{targetResourceId}/.default", "默认访问目标资源的权限" }
    }
});

内容的提问来源于stack exchange,提问作者user1075940

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:03:19