You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

本地Express调用Bol Retailer API遇403,Postman可正常请求

对接Bol Retailer API获取令牌时的403错误问题与代码对比

问题背景

正在对接Bol Retailer API,使用Express Node.js服务器通过Axios发起请求获取令牌,本地服务器返回403错误(提示"Unauthorized request",即请求合法但API拒绝访问)。用Postman通过OAuth2.0生成令牌后请求可正常运行,但自身代码始终报错,已尝试多种方法均无效,后找到一段可行代码,需明确两段代码的差异及解决思路。

报错代码片段

const express = require('express');
const axios = require('axios');

const app = express();

app.get('/getBolData', async (req, res) => {
    try {
        const clientId = <clientId>;
        const clientSecret = <clientSecret>;
        const credentials = btoa(clientId + ":" + clientSecret);

        const response = await axios.post('https://api.bol.com/token?grant_type=client_credentials', {
            headers: {
                'Access-Control-Allow-Methods': '*',
                'Accept': 'application/json',
                'Authorization': 'Basic ' + credentials
            },
        });

        res.json(response.data.acces_token);
    } catch (error) {
        if (error.response) {
            console.log('response', error.response.data);
            console.log('response', error.response.status);
            console.log('response', error.response.headers);
        } else if (error.request) {
            console.log('request', error.request);
        } else {
            console.log('Error', error.message);
        }
        res.status(500).send('Server error occured');
    }
});

app.listen(3000);

403错误日志

{ title: 'Unauthorized request', status: 403 }
Object [AxiosHeaders] {
  date: 'Thu, 21 Dec 2023 11:42:26 GMT',
  'content-type': 'application/problem+json',
  'content-length': '45',
  server: 'undefined',
  'x-envoy-decorator-operation': 'ingress-controller-eng-pro-bol-com-api.eng.svc.cluster.local:80/*',
  via: '1.1 google',
  'alt-svc': 'h3=":443"; ma=2592000,h3-29=":443"; ma=2592000'
}

已尝试的解决方法

  • 清除缓存和Cookie
  • 使用代理请求
  • 反复核对凭证和所需请求头
  • 启用CORS并更新服务器版本
  • 联系客服但未获得有效帮助

可行代码片段

const clientId = <clientId>;
const clientSecret = <clientSecret>;
const credentials = btoa(clientId + ":" + clientSecret);

let config = {
  method: 'post',
  url: 'https://login.bol.com/token?grant_type=client_credentials',
  headers: { 
    'Authorization': 'Basic ' + credentials, 
    'Accept': 'application/json',
  }
};

axios.request(config)
.then((response) => {
    res.json(response.data.access_token);
  console.log(JSON.stringify(response.data));
})
.catch((error) => {
  console.log(error);
});

两段代码的核心差异与解决建议

核心差异

  1. 请求URL错误:报错代码使用https://api.bol.com/token,而Bol的OAuth令牌正确端点是https://login.bol.com/token,这是导致403的关键原因之一。
  2. Axios调用参数错误:axios.post的参数格式为axios.post(url, data, config),报错代码把headers放在了第二个参数(请求体位置),导致请求头未被正确携带,API无法验证身份。可行代码使用axios.request传入完整配置对象,参数格式正确。
  3. 多余的请求头:报错代码中添加了Access-Control-Allow-Methods,这是服务器返回给前端的响应头,作为请求头发送不仅无效,还可能干扰API的验证逻辑。
  4. 响应字段拼写错误:报错代码中写的是response.data.acces_token,正确字段名是access_token(少了一个s)。

解决建议

  • 替换令牌请求URL为https://login.bol.com/token
  • 正确使用Axios POST方法:要么将headers放在第三个参数的config中,示例:
    const response = await axios.post(
      'https://login.bol.com/token?grant_type=client_credentials',
      {}, // POST请求体,client_credentials模式下无需内容
      { headers: { 'Authorization': 'Basic ' + credentials, 'Accept': 'application/json' } }
    );
    
  • 移除不必要的请求头(如Access-Control-Allow-Methods)
  • 修正响应字段的拼写错误,确保为access_token

内容的提问来源于stack exchange,提问作者Diégo Cup

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.03 22:15:02