在Zoho Flow的Deluge中实现Adobe Sign OAuth无法跳转登录页求助
问题:Zoho Flow中Deluge调用Adobe Sign OAuth未触发登录页跳转
我正在学习Deluge,目前在Zoho Flow中测试与Adobe Sign的集成。按照预期,代码执行后应跳转至Adobe Sign登录页,但实际并未实现此效果,请求帮助。
Adobe文档中的授权请求URL
https://secure.na4.adobesign.com/public/oauth/v2?redirect_uri=https://example.com/oauthDemo&response_type=code&client_id=d4HQNPFIXFD255H&scope=user_login:self+agreement_write:account&state=S6YQD7KDA556DIV6NAU4ELTGSIV26ZNMXDSF7WIEEP0ZLQCLDQ89OYG78C3K9SROC8DXCGRVSGKU1IT1
我编写的Deluge代码
void _CreateAdobeDocument() { // Part 1 : Authenticate Adobe and Create Document //// OAuth Token Exchange authCodeParams = Map(); authCodeParams.put("response_type","code"); authCodeParams.put("client_id",{"My-client-id"}); authCodeParams.put("redirect_uri","https://www.bigin.zoho.com"); authCodeParams.put("scope","agreement_read:account+agreement_write:account+agreement_send:account"); authCodeResponse = invokeurl [ url :"https://secure.na4.adobesign.com/public/oauth/v2?redirect_uri=https://www.bigin.zoho.com&response_type=code&client_id={My-client-ID}&scope=agreement_read:account+agreement_write:account+agreement_send:account" type :GET detailed:TRUE ]; info authCodeResponse; }
执行返回的响应信息(节选)
{ "date": "Wed, 03 Apr 2024 21:33:43 GMT", "server": "Apache", "vary": "Accept-Encoding", "3p": "CP=\"IDC DSP COR ADM DEVi TAIi PSA PSD IVAi IVDi CONi HIS OUR IND CNT\"", "pragma": "no-cache", "strict-transport-security": "max-age=31536000; includeSubDomains;", "set-cookie": "JSESSIONID=D98A6A8A9B0B26C9F95C9D6E06A6F174.app-b18; Path=/; Domain=.na4.adobesign.com; HttpOnly; SameSite=None; Secure", "keep-alive": "timeout=15, max=200", "x-xss-protection": "1; mode=block", "x-content-type-options": "nosniff", "x-robots-tag": "none", "content-security-policy-report-only": "frame-ancestors 'self' ;report-uri /api/gateway/loggingserver/csp?source=adobesignprod&requestId=240403143454274.803&sessionId=CBHCRABAAA7V4Hdx9XHaWrmpRzGQVG5X3Nv4-O4s1giS_D4LhX8FM.app-b23&loginAccount=&embeddingApp=;", "connection": "Keep-Alive", "content-type": "text/html;charset=UTF-8", "cache-control": "no-cache, no-store, must-revalidate, max-age=0, private", "content-language": "en-US" }, "responseCode": 200
问题分析与解决建议
核心原因:
invokeurl是Zoho Flow服务器端发起的HTTP请求,返回的登录页HTML只会被服务器接收,无法触发用户浏览器的跳转。OAuth授权码流程的第一步必须在用户浏览器中打开授权URL,而非后端调用。具体修正步骤:
- 调整触发方式:放弃用
invokeurl发起授权请求,改为引导用户在前端打开Adobe Sign授权URL。比如在Zoho Flow中使用支持重定向的组件,或在用户交互界面提供跳转链接。 - 完善URL参数:
- 确保
redirect_uri已在Adobe Sign开发者后台完成注册,且与代码中使用的地址完全一致; - 添加
state参数(参考Adobe文档示例),防范CSRF攻击; - 给
scope补充user_login:self权限,这是触发用户登录的必要参数。
- 确保
- 处理回调逻辑:用户授权后会跳转到
redirect_uri,此时在该地址处接收code参数,再用invokeurl发起POST请求完成令牌交换(用code换取access_token)。
- 调整触发方式:放弃用
内容的提问来源于stack exchange,提问作者StullerDesign
相关产品推荐
相关产品推荐

