本地Express调用Bol Retailer API遇403,Postman可正常请求
对接Bol Retailer API获取令牌时的403错误问题与代码对比
问题背景
正在对接Bol Retailer API,使用Express Node.js服务器通过Axios发起请求获取令牌,本地服务器返回403错误(提示"Unauthorized request",即请求合法但API拒绝访问)。用Postman通过OAuth2.0生成令牌后请求可正常运行,但自身代码始终报错,已尝试多种方法均无效,后找到一段可行代码,需明确两段代码的差异及解决思路。
报错代码片段
const express = require('express'); const axios = require('axios'); const app = express(); app.get('/getBolData', async (req, res) => { try { const clientId = <clientId>; const clientSecret = <clientSecret>; const credentials = btoa(clientId + ":" + clientSecret); const response = await axios.post('https://api.bol.com/token?grant_type=client_credentials', { headers: { 'Access-Control-Allow-Methods': '*', 'Accept': 'application/json', 'Authorization': 'Basic ' + credentials }, }); res.json(response.data.acces_token); } catch (error) { if (error.response) { console.log('response', error.response.data); console.log('response', error.response.status); console.log('response', error.response.headers); } else if (error.request) { console.log('request', error.request); } else { console.log('Error', error.message); } res.status(500).send('Server error occured'); } }); app.listen(3000);
403错误日志
{ title: 'Unauthorized request', status: 403 } Object [AxiosHeaders] { date: 'Thu, 21 Dec 2023 11:42:26 GMT', 'content-type': 'application/problem+json', 'content-length': '45', server: 'undefined', 'x-envoy-decorator-operation': 'ingress-controller-eng-pro-bol-com-api.eng.svc.cluster.local:80/*', via: '1.1 google', 'alt-svc': 'h3=":443"; ma=2592000,h3-29=":443"; ma=2592000' }
已尝试的解决方法
- 清除缓存和Cookie
- 使用代理请求
- 反复核对凭证和所需请求头
- 启用CORS并更新服务器版本
- 联系客服但未获得有效帮助
可行代码片段
const clientId = <clientId>; const clientSecret = <clientSecret>; const credentials = btoa(clientId + ":" + clientSecret); let config = { method: 'post', url: 'https://login.bol.com/token?grant_type=client_credentials', headers: { 'Authorization': 'Basic ' + credentials, 'Accept': 'application/json', } }; axios.request(config) .then((response) => { res.json(response.data.access_token); console.log(JSON.stringify(response.data)); }) .catch((error) => { console.log(error); });
两段代码的核心差异与解决建议
核心差异
- 请求URL错误:报错代码使用
https://api.bol.com/token,而Bol的OAuth令牌正确端点是https://login.bol.com/token,这是导致403的关键原因之一。 - Axios调用参数错误:
axios.post的参数格式为axios.post(url, data, config),报错代码把headers放在了第二个参数(请求体位置),导致请求头未被正确携带,API无法验证身份。可行代码使用axios.request传入完整配置对象,参数格式正确。 - 多余的请求头:报错代码中添加了
Access-Control-Allow-Methods,这是服务器返回给前端的响应头,作为请求头发送不仅无效,还可能干扰API的验证逻辑。 - 响应字段拼写错误:报错代码中写的是
response.data.acces_token,正确字段名是access_token(少了一个s)。
解决建议
- 替换令牌请求URL为
https://login.bol.com/token - 正确使用Axios POST方法:要么将headers放在第三个参数的config中,示例:
const response = await axios.post( 'https://login.bol.com/token?grant_type=client_credentials', {}, // POST请求体,client_credentials模式下无需内容 { headers: { 'Authorization': 'Basic ' + credentials, 'Accept': 'application/json' } } ); - 移除不必要的请求头(如
Access-Control-Allow-Methods) - 修正响应字段的拼写错误,确保为
access_token
内容的提问来源于stack exchange,提问作者Diégo Cup
相关产品推荐
相关产品推荐

