You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OAuth 1.0签名生成排障:无法复现Postman的正确签名

OAuth 1.0 HMAC-SHA256签名无法与Postman生成结果匹配,求排查思路

我已经研究这个问题好几天了,急需新的排查方向。我知道这是OAuth 1.0签名的常见问题,网上大部分解决方案都是“确保参数按字母排序”或“不要遗漏&符号”,但我确定这些都不是我的问题。和很多发帖求助的人一样,我自己生成的签名始终和Postman的对不上。

我的场景细节:

  • 所有要调用的API都是POST请求,提交的请求体数据不影响签名生成
  • 请求URL原本带有一些参数,但根据API文档,POST请求不需要携带这些参数,而且在Postman里删除这些参数后,签名结果完全不受影响
  • 签名所需的参数只有OAuth 1.0规定的必填项:consumer key、nonce、签名方法、timestamp、token和version,参数范围很明确,不会混淆
  • 我需要在自定义脚本语言/界面中实现,现成的OAuth库或预构建方案都用不了。我已经对比过Java、JavaScript、Perl等多种语言的代码片段,逻辑上都是一致的。如果有工具能显示签名生成过程中的预编码字符串,对我排查问题会有极大帮助。

我已经在Upwork发布了付费需求,愿意付费寻求解决方案。

以下是我的测试代码:

//test values
requestURL = "https://myURL.com/subdirectory?param1=10&param2=0"
realm = "90210"
consKey = "555588884444777733336666"
token="111166662222777733338888"
sigMethod="HMAC-SHA256"
timestamp="1687965335"
nonce="10E7ZKnuxDf"
oauthVersion="1.0"
requestMethod = "POST"
consumer_Secret = "1"
token_secret = "2"

//strip params out of URL
url = requestURL.split("?")
reqParams = url[1]
baseURL = url[0]

//compile parameter string
data = ""
if requestMethod.upper() = "GET"
{
    data.append("{reqParams}&")
}
data.append("oauth_consumer_key={consKey}&")
data.append("oauth_nonce={nonce}&")
data.append("oauth_signature_method={sigMethod}&")
data.append("oauth_timestamp={timestamp}&")
data.append("oauth_token={token}&")
data.append("oauth_version={oauthVersion}")

//compile signature string
sigString = "{requestMethod.upper()}&{baseURL.urlencode()}&{data.urlencode()}"

//correct capitalization per OAuth 1.0 standard
sigString = sigString.replace("%3a","%3A").replace("%2f","%2F").replace("%3d","%3D")

//use proxy function to encrypt
proxy = getRestProxy()
oauthSig = proxy.EncodeHS256("{sigString}","{consumer_Secret}&{token_secret}")
oauthSig = "{oauthSig.trim()}" 
//(found a post saying their encoding added a hard return, doesn't seem to be an issue in my custom scripting language)

//re-urlencode. hashed values should have +,-,_,/
oauthSig = oauthSig.replace("-","+").replace("_","/")
oauthSig = oauthSig.replace("+","%2B").replace("/","%2F")
oauthSig.append("%3D") //pad with =


//oauthSig=nyEyepA7lXiaR0HRZPMDQHTPdJEZMyMy7uEpEAIjFyw%3D //from my script
//oauth_signature="lv%2BbohpHYqR23LIs4XqFjyA3wtwxayZltoiYT6ss0ms%3D" //from postman

内容的提问来源于stack exchange,提问作者Jared H

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 14:53:14