OAuth 1.0签名生成排障:无法复现Postman的正确签名
OAuth 1.0 HMAC-SHA256签名无法与Postman生成结果匹配,求排查思路
我已经研究这个问题好几天了,急需新的排查方向。我知道这是OAuth 1.0签名的常见问题,网上大部分解决方案都是“确保参数按字母排序”或“不要遗漏&符号”,但我确定这些都不是我的问题。和很多发帖求助的人一样,我自己生成的签名始终和Postman的对不上。
我的场景细节:
- 所有要调用的API都是POST请求,提交的请求体数据不影响签名生成
- 请求URL原本带有一些参数,但根据API文档,POST请求不需要携带这些参数,而且在Postman里删除这些参数后,签名结果完全不受影响
- 签名所需的参数只有OAuth 1.0规定的必填项:consumer key、nonce、签名方法、timestamp、token和version,参数范围很明确,不会混淆
- 我需要在自定义脚本语言/界面中实现,现成的OAuth库或预构建方案都用不了。我已经对比过Java、JavaScript、Perl等多种语言的代码片段,逻辑上都是一致的。如果有工具能显示签名生成过程中的预编码字符串,对我排查问题会有极大帮助。
我已经在Upwork发布了付费需求,愿意付费寻求解决方案。
以下是我的测试代码:
//test values requestURL = "https://myURL.com/subdirectory?param1=10¶m2=0" realm = "90210" consKey = "555588884444777733336666" token="111166662222777733338888" sigMethod="HMAC-SHA256" timestamp="1687965335" nonce="10E7ZKnuxDf" oauthVersion="1.0" requestMethod = "POST" consumer_Secret = "1" token_secret = "2" //strip params out of URL url = requestURL.split("?") reqParams = url[1] baseURL = url[0] //compile parameter string data = "" if requestMethod.upper() = "GET" { data.append("{reqParams}&") } data.append("oauth_consumer_key={consKey}&") data.append("oauth_nonce={nonce}&") data.append("oauth_signature_method={sigMethod}&") data.append("oauth_timestamp={timestamp}&") data.append("oauth_token={token}&") data.append("oauth_version={oauthVersion}") //compile signature string sigString = "{requestMethod.upper()}&{baseURL.urlencode()}&{data.urlencode()}" //correct capitalization per OAuth 1.0 standard sigString = sigString.replace("%3a","%3A").replace("%2f","%2F").replace("%3d","%3D") //use proxy function to encrypt proxy = getRestProxy() oauthSig = proxy.EncodeHS256("{sigString}","{consumer_Secret}&{token_secret}") oauthSig = "{oauthSig.trim()}" //(found a post saying their encoding added a hard return, doesn't seem to be an issue in my custom scripting language) //re-urlencode. hashed values should have +,-,_,/ oauthSig = oauthSig.replace("-","+").replace("_","/") oauthSig = oauthSig.replace("+","%2B").replace("/","%2F") oauthSig.append("%3D") //pad with = //oauthSig=nyEyepA7lXiaR0HRZPMDQHTPdJEZMyMy7uEpEAIjFyw%3D //from my script //oauth_signature="lv%2BbohpHYqR23LIs4XqFjyA3wtwxayZltoiYT6ss0ms%3D" //from postman
内容的提问来源于stack exchange,提问作者Jared H
相关产品推荐
相关产品推荐

