如何在WSO2 DevPortal中获取指定Scope的OAuth访问令牌?
问题描述
我正尝试为已发布的某API获取OAuth访问令牌,已为该API资源定义了本地Scope「XYZ_Scope」。通过DevPortal的UI可以生成包含该指定Scope的令牌,但使用curl命令却无法实现。
当前使用的curl命令如下:
curl --location 'https://{your-ip-address}:9443/oauth2/token' \ --header 'Authorization: Basic Base64(consumer-key:consumer-secret)' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'grant_type=password' \ --data-urlencode 'username=username' \ --data-urlencode 'password=password'
返回的响应内容为:
{ "access_token": "*token*", "scope": "default", "token_type": "Bearer", "expires_in": 3600 }
使用该访问令牌无法访问已发布的API,遇到的错误信息如下:
{ "code": "900910", "message": "The access token does not allow you to access the requested resource", "description": "User is NOT authorized to access the Resource: /{device-name}/{resource-name}. Scope validation failed." }
请问是否可以在curl命令中添加自定义的本地Scope来获取对应的访问令牌?
解决方案
可以在curl命令中添加自定义Scope,只需在请求的表单数据里增加scope参数并指定「XYZ_Scope」即可。
修改后的curl命令如下:
curl --location 'https://{your-ip-address}:9443/oauth2/token' \ --header 'Authorization: Basic Base64(consumer-key:consumer-secret)' \ --header 'Content-Type: application/x-www-form-urlencoded' \ --data-urlencode 'grant_type=password' \ --data-urlencode 'username=username' \ --data-urlencode 'password=password' \ --data-urlencode 'scope=XYZ_Scope'
执行该命令后,返回的访问令牌会包含「XYZ_Scope」,使用此令牌访问目标API即可通过Scope校验。
如果需要同时申请多个Scope,可用空格分隔不同Scope名称,例如:scope=XYZ_Scope another_custom_scope。
内容的提问来源于stack exchange,提问作者James
相关产品推荐
相关产品推荐

