Không thể nhận mã làm mới của https://management.azure.com/ bằng PowerShell
Aug 21 2020
Tôi đang cố lấy mã thông báo Access và mã thông báo làm mới cho tài nguyên "https://management.azure.com/" bằng PowerShell, nhưng tôi nhận được một mã thông báo Access duy nhất. Tôi cũng cần một mã thông báo làm mới. Tôi chia sẻ mã của tôi như dưới đây.
$clientID = '1xxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' $secretKey = 'kdfudifkldfliKASDFKkdfjd-ddkjfidysikd'
$tenantID = 'fxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx' $password = ConvertTo-SecureString -String $secretKey -AsPlainText -Force $credential = New-Object System.Management.Automation.PSCredential($ClientID,$password)
Connect-AzureRmAccount -ServicePrincipal -Credential $credential -Tenant $tenantID
$authUrl = "https://login.windows.net/" + $tenantID + "/oauth2/token/"
$body = @{ "resource" = "https://management.azure.com/"; "grant_type" = "client_credentials"; "client_id" = $ClientID
"client_secret" = $secretKey } Write-Output "Getting Authentication-Token ..." $adlsToken = Invoke-RestMethod -Uri $authUrl –Method POST -Body $body
Write-Output $adlsToken
------------ đầu ra ---------------
Getting Authentication-Token ...
token_type : Bearer
expires_in : 3599
ext_expires_in : 3599
expires_on : 1597999269
not_before : 1597995369
resource : https://management.azure.com/
access_token : J0uYFoioURT4CdISuUrRrr...
Trả lời
CarlZhao Aug 21 2020 at 11:04
Spec khẳng định các Thông tin đăng nhập Khách hàng cấp loại PHẢI KHÔNG cho phép phát hành các thẻ làm mới. Vì vậy, câu trả lời là, bạn phải sử dụng một loại tài trợ khác để nhận mã làm mới với mã thông báo truy cập của bạn.
Do đó, bạn nên sử dụng luồng mã xác thực , luồng này sẽ trả lại mã thông báo làm mới cho bạn khi bạn yêu cầu mã thông báo.
Cập nhật: