【问题标题】:oauth on appengine: access issueappengine 上的 oauth:访问问题
【发布时间】:2011-04-04 22:23:58
【问题描述】:

我在通过 AppEngine 上的 OAuth 访问资源时遇到了一些困难。

我的客户端应用程序(在 Linux 上使用 python-oauth)能够检索有效的“访问令牌”,但是当我尝试访问受保护的资源(例如 user = oauth.get_current_user())时,我得到了一个 oauth.OAuthRequestError 异常抛出。

headers: {'Content-Length': '21', 'User-Agent': 'musync,gzip(gfe),gzip(gfe)', 'Host': 'services.systemical.com', 'X-Google-Apps-Metadata': 'domain=systemical.com', 'X-Zoo': 'app-id=services-systemical,domain=systemical.com', 'Content-Type': 'application/json', 'Authorization': 'OAuth oauth_nonce="03259912", oauth_timestamp="1282928181", oauth_consumer_key="services.systemical.com", oauth_signature_method="HMAC-SHA1", oauth_version="1.0", oauth_token="1%2Fo0-tcGTfRzkkm449qVxd_8CfCvMcW_0xwL024nO3HgI", oauth_signature="2ojSK6Ws%2BvDxx3Rdlltf53hlI2w%3D"'}

我怀疑该问题可能与域相关,即我在 services.systemical.com 上使用端点,而我看到 AppEngine 为 X-Google-Apps-Metadata 报告 domain=systemical.com

我该如何解决这个问题?我在 Apps/AppEngine 中使用子域的方式有问题吗?


域“services.systemical.com”指向(DNS CNAME)我的 appengine 应用程序services-systemical.appspot.com。域 systemical.com 与 Google Apps 域相关联。


更新:这是我正在使用的客户端代码:

class OauthClient(object):

    gREQUEST_TOKEN_URL = 'OAuthGetRequestToken'
    gACCESS_TOKEN_URL =  'OAuthGetAccessToken'
    gAUTHORIZATION_URL = 'OAuthAuthorizeToken'

    def __init__(self, server, port, base):
        self.server=server
        self.port=port
        self.base=base
        self.request_token_url=self.base+self.gREQUEST_TOKEN_URL
        self.access_token_url=self.base+self.gACCESS_TOKEN_URL
        self.authorize_token_url=self.base+self.gAUTHORIZATION_URL
        self.connection = httplib.HTTPConnection("%s:%d" % (self.server, self.port))

    def fetch_request_token(self, oauth_request):
        self.connection.request(oauth_request.http_method, self.request_token_url, headers=oauth_request.to_header()) 
        response = self.connection.getresponse()
        print response.status, response.reason
        print response.msg
        return oauth.OAuthToken.from_string(response.read())

    def fetch_access_token(self, oauth_request):
        self.connection.request(oauth_request.http_method, self.access_token_url, headers=oauth_request.to_header()) 
        response = self.connection.getresponse()
        return oauth.OAuthToken.from_string(response.read())

    def authorize_token(self, oauth_request):
        self.connection.request(oauth_request.http_method, oauth_request.to_url()) 
        response = self.connection.getresponse()
        return response.read()

【问题讨论】:

    标签: python google-app-engine oauth


    【解决方案1】:

    我遇到了类似的问题。虽然我不能更具体(我没有代码),但我可以告诉你问题可能与请求有关。 Google App Engine 对您提出的要求非常挑剔。

    尝试发送空的请求正文。例如,这是通常的调用:

    import httplib
    connection = httplib.HTTPSConnection('server.com')
    connection.request('POST', REQUEST_TOKEN_URL,body = urlencode(body), headers = {'Authorization': header})
    

    但你应该发送一个空的正文:

    connection.request('POST', REQUEST_TOKEN_URL, headers = {'Authorization': header})
    

    标头包含 OAuth 所需的所有信息。

    【讨论】:

    • 我已经更新了问题:我只使用“标头”进行令牌请求:我仍然有问题。
    猜你喜欢
    • 2011-07-01
    • 2012-03-27
    • 2015-01-22
    • 1970-01-01
    • 2011-07-22
    • 2021-10-27
    • 2013-12-26
    • 2016-07-18
    • 2012-10-20
    相关资源
    最近更新 更多