简体   繁体   English

Microsoft graph API doesn't save session token after successful login and token retrieval in Python Flask session

[英]Microsoft graph API doesn't save session token after successful login and token retrieval in Python Flask session

I have cloned a simple Microsoft graph login API from the official graph developers docs and changed the app config variables as per my registered app.我从官方图形开发者文档中克隆了一个简单的 Microsoft 图形登录 API,并根据我注册的应用程序更改了应用程序配置变量。 The authentication works successfully, but it's stuck at graphCall method where i redirect the user after a successful user authentication.身份验证成功运行,但它停留在graphCall方法,我在成功的用户身份验证后重定向用户。 The console shows the token string, but it still redirects the user to my index page where the login button lays.控制台显示了令牌字符串,但它仍然将用户重定向到我的登录按钮所在的索引页面。

my full app file looks the following:我的完整应用程序文件如下所示:

import uuid
import requests
from flask import Flask, render_template, session, request, redirect, url_for
from flask_session import Session  # https://pythonhosted.org/Flask-Session
import msal
import app_config

app = Flask(__name__)

def index():
    if not session.get("user"):
        return redirect(url_for("login"))
    return render_template('index.html', user=session["user"], version=msal.__version__)

# @app.route("/getAToken")
# def getAToken():
#     if not session.get("user"):
#         return redirect(url_for("login"))
#     return render_template('getAToken.html')

def login():
    session["state"] = str(uuid.uuid4())
    # Technically we could use empty list [] as scopes to do just sign in,
    # here we choose to also collect end user consent upfront
    auth_url = _build_auth_url(scopes=app_config.SCOPE, state=session["state"])
    return render_template("login.html", auth_url=auth_url, version=msal.__version__)

@app.route(app_config.REDIRECT_PATH)  # Its absolute URL must match your app's redirect_uri set in AAD
def authorized():
    if request.args.get('state') != session.get("state"):
        return redirect(url_for("index"))  # No-OP. Goes back to Index page
    if "error" in request.args:  # Authentication/Authorization failure
        return render_template("auth_error.html", result=request.args)
    if request.args.get('code'):
        cache = _load_cache()
        result = _build_msal_app(cache=cache).acquire_token_by_authorization_code(
            scopes=app_config.SCOPE,  # Misspelled scope would cause an HTTP 400 error here
            redirect_uri=url_for("authorized", _external=True))
        if "error" in result:
            return render_template("auth_error.html", result=result)
        session["user"] = result.get("id_token_claims")
    return redirect(url_for("index"))

def logout():
    session.clear()  # Wipe out user and its token cache from session
    return redirect(  # Also logout from your tenant's web session
        app_config.AUTHORITY + "/oauth2/v2.0/logout" +
        "?post_logout_redirect_uri=" + url_for("index", _external=True))

def graphcall():
    token = _get_token_from_cache(app_config.SCOPE)
    if not token:
        return redirect(url_for("login"))
    graph_data = requests.get(  # Use token to call downstream service
        headers={'Authorization': 'Bearer ' + token['access_token']},
    return render_template('display.html', result=graph_data)

def _load_cache():
    cache = msal.SerializableTokenCache()
    if session.get("token_cache"):
    return cache

def _save_cache(cache):
    if cache.has_state_changed:
        session["token_cache"] = cache.serialize()

def _build_msal_app(cache=None, authority=None):
    return msal.ConfidentialClientApplication(
        app_config.CLIENT_ID, authority=authority or app_config.AUTHORITY,
        client_credential=app_config.CLIENT_SECRET, token_cache=cache)

def _build_auth_url(authority=None, scopes=None, state=None):
    return _build_msal_app(authority=authority).get_authorization_request_url(
        scopes or [],
        state=state or str(uuid.uuid4()),
        redirect_uri=url_for("authorized", _external=True))

def _get_token_from_cache(scope=None):
    cache = _load_cache()  # This web app maintains one cache per session
    cca = _build_msal_app(cache=cache)
    accounts = cca.get_accounts()
    if accounts:  # So all account(s) belong to the current signed-in user
        result = cca.acquire_token_silent(scope, account=accounts[0])
        return result

app.jinja_env.globals.update(_build_auth_url=_build_auth_url)  # Used in template

if __name__ == "__main__":

According to my understanding, you want to redirect to /graphcall after your successful authentication, and it can be done my just modifying the code as shown below.根据我的理解,你想在认证成功后重定向到/graphcall,我只需修改如下代码即可。

def authorized():
    if request.args.get('state') != session.get("state"):
        return redirect(url_for("graphcall")) 
    if "error" in request.args: 
        return render_template("auth_error.html", result=request.args)
    if request.args.get('code'):
        cache = _load_cache()
        result = _build_msal_app(cache=cache).acquire_token_by_authorization_code(
            redirect_uri=url_for("authorized", _external=True))
        if "error" in result:
            return render_template("auth_error.html", result=result)
        session["user"] = result.get("id_token_claims")
    return redirect(url_for("graphcall"))

You would be having an issue with the back button, you can change it to / in href so that it goes to index page.您会遇到后退按钮的问题,您可以将其更改为 / in href 以便它转到索引页面。 Let me know if you need any more help.如果您需要更多帮助,请告诉我。

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

粤ICP备18138465号  © 2020-2024 STACKOOM.COM