SpringBoot集成Spotify API授权仅单次可用问题求助
Spotify API + SpringBoot 授权异常:仅单次授权有效,需等待3600秒才可再次授权
我正在使用Spotify API和SpringBoot开发项目,遇到了用户授权的问题:仅能完成一次授权操作,之后无论是同一账号还是其他账号,都必须等待3600秒才能再次发起授权,这给开发和使用带来了极大困扰。我尝试过为每个用户生成随机state、通过refresh token更新access token,但都没能解决问题,希望能得到可行的解决方案或建议。
参考仓库:spotify-web-api-java
登录接口代码
@GetMapping("/login") public ResponseEntity<Map<String, String>> spotifyLogin() { try { String state = generateRandomString(16); stateStore.put(state, "pending"); SpotifyApi spotifyApi = spotifyConfiguration.getSpotifyObject(); AuthorizationCodeUriRequest authorizationCodeUriRequest = spotifyApi.authorizationCodeUri() .scope("user-library-read user-top-read") .state(state) .show_dialog(true) .build(); URI uri = authorizationCodeUriRequest.execute(); Map<String, String> response = new HashMap<>(); response.put("spotifyAuthUrl", uri.toString()); return ResponseEntity.ok(response); } catch (Exception e) { return ResponseEntity.status(HttpStatus.INTERNAL_SERVER_ERROR) .body(Map.of("error", "Unexpected error: " + e.getMessage())); } }
回调接口代码
@GetMapping("/callback") public ResponseEntity<Map<String, Object>> getSpotifyUserCode( @RequestParam("code") String userCode, @RequestParam("state") String state) throws IOException, ParseException, SpotifyWebApiException { try { SpotifyApi spotifyApi = spotifyConfiguration.getSpotifyObject(); AuthorizationCodeRequest authorizationCodeRequest = spotifyApi.authorizationCode(userCode).build(); AuthorizationCodeCredentials authorizationCode = authorizationCodeRequest.execute(); spotifyApi.setAccessToken(authorizationCode.getAccessToken()); spotifyApi.setRefreshToken(authorizationCode.getRefreshToken()); GetCurrentUsersProfileRequest getCurrentUsersProfile = spotifyApi.getCurrentUsersProfile().build(); User user = getCurrentUsersProfile.execute(); if (userProfileService.userExists(user.getId())) { if (userProfileService.isTokenExpired(user.getId())) { spotifyApi = refreshAccessToken(userProfileService.getRefreshToken(user.getId()), user.getId()); } } userProfileService.InsertOrUpdateUserDetails(user, spotifyApi.getAccessToken(), spotifyApi.getRefreshToken()); Map<String, Object> responseData = new HashMap<>(); responseData.put("userId", user.getId()); responseData.put("username", user.getDisplayName()); responseData.put("email", user.getEmail()); responseData.put("accessToken", spotifyApi.getAccessToken()); responseData.put("refreshToken", spotifyApi.getRefreshToken()); responseData.put("country", user.getCountry()); responseData.put("displayName", user.getDisplayName()); return ResponseEntity.ok(responseData); } catch (Exception e) { Map<String, Object> errorResponse = new HashMap<>(); errorResponse.put("error", "Error processing Spotify user code: " + e.getMessage()); return ResponseEntity.status(HttpStatus.INTERNAL_SERVER_ERROR).body(errorResponse); } }
测试过程与结果
- 首次尝试:
- 调用
/api/login,返回redirectURI/code="",符合预期; - 调用
/api/callback?code=val1&state=val2,正确返回包含用户信息及access/refresh token的JSON。
- 调用
- 第二次尝试:
- 调用
/api/login,返回redirectURI/code="",符合预期; - 调用
/api/callback?code=val1&state=val2,返回错误:{ "error": "Error processing Spotify user code: Forbidden" }
- 调用
注:等待3600秒(授权code过期)后,可再次完成一次授权操作,之后重复上述循环。
内容的提问来源于stack exchange,提问作者Aradhya Sharma
相关产品推荐
相关产品推荐

