使用Flask-OAuthlib调用LinkedIn API时遇404错误求助
Flask-OAuthlib集成LinkedIn API时/userinfo接口404错误问题
问题概述
使用Flask-OAuthlib开发Flask应用,完成LinkedIn OAuth认证流程后,调用linkedin.get('/userinfo')接口返回404错误,无法正常获取用户个人资料数据。
问题原因
- API基础路径配置错误:LinkedIn的
/userinfo属于OpenID Connect规范下的端点,其基础路径为https://api.linkedin.com/oauth/v2/,而非代码中配置的https://api.linkedin.com/v2/,错误的路径拼接导致请求地址无效,触发404。 - 权限范围配置不合理:
- 原配置的
w_member_social是写权限,获取用户资料无需该权限; - 缺少LinkedIn必需的读取权限
r_liteprofile和r_emailaddress,即使OpenID范围配置正确,也无法返回完整用户数据。
- 原配置的
解决方案
1. 修正API基础路径
将LinkedIn OAuth配置中的base_url修改为https://api.linkedin.com/oauth/v2/,确保/userinfo接口路径拼接正确。
2. 调整权限范围
更新request_token_params中的scope参数,保留OpenID核心范围并添加LinkedIn读取权限,同时移除无用的写权限:
'scope': ['openid', 'profile', 'email', 'r_liteprofile', 'r_emailaddress']
注:需在LinkedIn开发者后台确保应用已申请并启用上述权限。
3. 简化请求逻辑
Flask-OAuthlib的remote_app.get()方法会自动携带access token,无需手动添加Authorization请求头,可移除自定义headers参数。
修改后的完整代码
import io import json import logging import openai import requests from flask import Flask, request, jsonify, session, redirect, abort, url_for from flask_oauthlib.client import OAuth from pip._vendor import cachecontrol # Flask app setup app = Flask(__name__) app.secret_key = "secret_key" # OAuth setup with LinkedIn oauth = OAuth(app) linkedin = oauth.remote_app( 'Ety', consumer_key='YOUR_CONSUMER_KEY', consumer_secret='YOUR_CONSUMER_SECRET', request_token_params={ 'scope': ['openid', 'profile', 'email', 'r_liteprofile', 'r_emailaddress'] }, base_url='https://api.linkedin.com/oauth/v2/', request_token_url=None, access_token_method='POST', access_token_url='https://www.linkedin.com/oauth/v2/accessToken', authorize_url='https://www.linkedin.com/oauth/v2/authorization' ) # LinkedIn tokengetter function @linkedin.tokengetter def get_linkedin_oauth_token(): return session.get('linkedin_token') # LinkedIn login route @app.route('/auth/linkedin') def linkedin_login(): return linkedin.authorize(callback=url_for('linkedin_authorized', _external=True)) # LinkedIn authorized route @app.route('/auth/linkedin/authorized') def linkedin_authorized(): response = linkedin.authorized_response() if response is None or response.get('access_token') is None: return 'Access denied: reason={} error={}'.format( request.args['error_reason'], request.args['error_description'] ) session['linkedin_token'] = (response['access_token'], '') # 自动携带token,无需手动添加headers me_response = linkedin.get('/userinfo') me_data = me_response.data print(me_response.status) print(me_data) linkedin_id = me_data['sub'] session['linkedin_id'] = linkedin_id session['name'] = me_data['name'] return redirect('/')
内容的提问来源于stack exchange,提问作者Alex Tyutyunnik
相关产品推荐
相关产品推荐

