无法从Webex获取授权码,重定向至未监听端点报错
我正在构建一套从Webex获取授权码(authorize code)的API架构:体验API(http://localhost:8081/captures/query)调用系统API(http://localhost:8081/authorize),再由系统API调用Webex的OAuth授权URL。
在浏览器触发体验API时,会先要求输入用户名和密码,随后页面重定向至http://localhost:8081/idb/globalLogin,并报错:No listener for endpoint: /idb/globalLogin,不清楚该重定向的原因,请求排查问题。
相关信息
- 体验API地址:
http://localhost:8081/captures/query - 系统API地址:
http://localhost:8081/authorize - Webex OAuth授权URL:
https://webexapis.com/v1/authorize?client_id=1234&response_type=code&redirect_uri=http://localhost:8081/captures/query&scope=meeting:recordings_read meeting:recordings_write spark:calls_read spark:kms spark:places_write spark:rooms_read
代码片段
体验API(exp API)
<flow name="exp" doc:id="99420f1e-76b8-4aca-8ed7-4fc6b2279db7" > <http:listener doc:name="Listener" doc:id="5b63c7e2-1310-4cfb-b5db-e0bfb383233b" config-ref="HTTP_Listener_config" path="/captures/query"/> <set-variable value='#[attributes.queryParams.code default ""]' doc:name="code" doc:id="8319a36e-1dcd-450f-b3d8-6359e3fff0e1" variableName="code" /> <logger level="INFO" doc:name="Logger" doc:id="ff26275e-7b18-4f6c-9ae9-15308c6f96d5" message="#[vars.code]"/> <choice doc:name="Choice" doc:id="d544cdee-9272-4296-a8eb-65a78797402e" > <when expression='vars.code ==""'> <http:request method="GET" doc:name="authorize" doc:id="e729c048-c160-481f-939c-131d9afea4f5" config-ref="HTTP_Request_configuration1" path="/authorize"> </http:request> </when> <otherwise > <http:request method="GET" doc:name="accesstoken" doc:id="1f59a999-1065-4123-b65d-7ccb4ddafeac" config-ref="HTTP_Request_configuration1" path="/accesstoken"> <http:query-params ><![CDATA[#[output application/java --- { "code" : vars.code }]]]></http:query-params> </http:request> </otherwise> </choice> </flow>
系统API(system API)
<flow name="get_authorize" doc:id="2c60da85-f3fc-433b-b45f-ce94d1664bbc" > <http:listener doc:name="Listener" doc:id="ba33fdab-f9c7-46cc-b65f-6e388936adcf" config-ref="HTTP_Listener_config" path="/authorize"/> <logger level="INFO" doc:name="Logger" doc:id="6f38f867-7315-42b0-b435-e7885229b9a8" message='authorize started'/> <ee:transform doc:name="queryParam" doc:id="89590b81-1043-4026-aca9-12983b4cd7e7" > <ee:message > <ee:set-payload ><![CDATA[output application/java --- { "response_type" : "code", "client_id" : "1234", "redirect_uri" : "http://localhost:8081/captures/query", "scope" : "meeting:recordings_read spark:kms spark:rooms_read spark:calls_read meeting:recordings_write spark:places_write" //"state": "test1234" }]]></ee:set-payload> </ee:message> </ee:transform> <http:request method="GET" doc:name="authorize" doc:id="34c4a0f4-64b6-4a7f-820d-aa730990af62" config-ref="HTTP_Request_configuration" path="/authorize"> <http:query-params><![CDATA[#[payload]]]></http:query-params> </http:request> <logger level="INFO" doc:name="Logger" doc:id="6edc9ded-92b0-4a55-bc78-91fd779e6fc2" message="authorize end"/> </flow>
问题排查分析
中间层认证拦截
/idb/globalLogin是MuleSoft Identity Broker(IDB)的默认登录端点,出现这个重定向说明你的应用或部署环境启用了IDB身份验证拦截。浏览器弹出的用户名密码输入框是IDB的验证环节,而非Webex的授权登录,当拦截到未携带有效凭证的请求时,会自动跳转至该登录端点。OAuth流程调用模式错误
Webex的授权码流程需要浏览器直接发起重定向请求,而非通过后端API转发。当前架构中,体验API通过后端HTTP请求调用系统API,再转发到Webex,这种后端代理的方式无法正确传递Webex的重定向响应,反而被IDB拦截。监听器配置问题
检查HTTP_Listener_config是否绑定了身份验证策略,或是环境中存在全局的认证规则,这些配置会自动拦截所有未认证的请求并跳转至IDB登录页面。
解决建议
- 调整授权流程逻辑:当体验API检测到
code为空时,直接使用<http:redirect>组件返回重定向响应,引导浏览器访问Webex的授权URL,移除后端调用系统API的环节。 - 关闭不必要的认证拦截:修改
HTTP_Listener_config,移除绑定的身份验证策略;如果是环境级别的拦截,联系管理员调整规则,放行/captures/query和/authorize端点。 - 验证Webex参数配置:确认Webex开发者后台已注册
redirect_uri,且client_id、scope参数与代码中配置一致。
内容的提问来源于stack exchange,提问作者Devendra

