Google OAuth回调Lambda端点未收到access_token,URL#后内容丢失
OAuth回调URL片段内容未被服务器接收的问题
问题现象
完成Google OAuth授权流程后,服务器(AWS API Gateway)未收到完整的回调URL,#之后的所有参数均被移除。
浏览器显示的完整回调URL
https://<domain>/google-drive/callback #access_token=<token> &token_type=Bearer&expires_in=3599 &scope=https://www.googleapis.com/auth/drive.file%20https://www.googleapis.com/auth/drive.install
服务器收到的APIGateway事件
{ "version": "2.0", "routeKey": "GET /google-drive/callback", "rawPath": "/google-drive/callback", "rawQueryString": "", "headers": { "accept": "text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8", "accept-encoding": "gzip, deflate, br", "accept-language": "en-US,en;q=0.5", "content-length": "0", "host": "kjndf98n49v.execute-api.us-east-1.amazonaws.com", "sec-fetch-dest": "document", "sec-fetch-mode": "navigate", "sec-fetch-site": "none", "sec-fetch-user": "?1", "upgrade-insecure-requests": "1", "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0", "x-amzn-trace-id": "Root=1-6609a719-148a9dd90fa586d725643c88", "x-forwarded-for": "68.23.54.13", "x-forwarded-port": "443", "x-forwarded-proto": "https" }, "queryStringParameters": {}, "requestContext": { "accountId": "87438545", "apiId": "kjndf98n49v", "domainName": "kjndf98n49v.execute-api.us-east-1.amazonaws.com", "domainPrefix": "kjndf98n49v", "http": { "method": "GET", "path": "/google-drive/callback", "protocol": "HTTP/1.1", "sourceIp": "65.30.11.25", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0" }, "requestId": "lkljSDLVK=", "routeKey": "GET /google-drive/callback", "stage": "$default", "time": "31/Mar/2024:18:10:33 +0000", "timeEpoch": 1711908633334 }, "isBase64Encoded": false }
当前使用的OAuth启动URL
https://accounts.google.com/o/oauth2/v2/auth ?client_id=<client-id> &redirect_uri=https://kjndf98n49v.execute-api.us-east-1.amazonaws.com/google-drive/callback &response_type=access_token &scope=https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.install
原因分析
当前使用的是OAuth隐式授权流程(response_type=access_token),该流程会将令牌等参数放在URL的片段(Fragment)(即#之后的部分)中。根据HTTP协议规范,浏览器在向服务器发送请求时,不会将URL片段传递给服务器,仅会在客户端本地保留这部分内容,因此服务器无法接收到#后的参数。
解决方案
改用OAuth授权码流程(Authorization Code Flow),步骤如下:
- 修改OAuth启动URL的
response_type参数为code:
https://accounts.google.com/o/oauth2/v2/auth ?client_id=<client-id> &redirect_uri=https://kjndf98n49v.execute-api.us-east-1.amazonaws.com/google-drive/callback &response_type=code &scope=https://www.googleapis.com/auth/drive.file https://www.googleapis.com/auth/drive.install
- 服务器收到授权码(
code参数)后,后台向Google的令牌端点发送请求,换取access_token等凭证。 - 该流程下,所有必要参数都会通过URL查询字符串传递,服务器可以正常接收。
内容的提问来源于stack exchange,提问作者TemporaryFix
相关产品推荐
相关产品推荐

