使用OAuth 2.0授权码流访问UNOS API时回调URI无法访问的问题
问题:OAuth2授权码模式访问UNOS API时无法访问回调URI
尝试使用OAuth 2.0授权码流程访问UNOS的特定API,但始终无法访问回调URI。以下是编写的Python脚本(已隐藏client_id和client_secret以保障安全),同时附上报错截图及API官方文档截图,文档明确了授权码请求、获取访问令牌等步骤的参数要求。
import base64 import hashlib import os import requests from flask import Flask, request, redirect from urllib.parse import urlencode, quote_plus app = Flask(__name__) def base64_urlencode(item): return base64.urlsafe_b64encode(item).rstrip(b'=') def create_code_verifier(size=64): verifier = base64_urlencode(os.urandom(size)).decode('utf-8') return verifier def create_code_challenge(verifier): sha256 = hashlib.sha256(verifier.encode('utf-8')).digest() return base64_urlencode(sha256).decode('utf-8') code_verifier = create_code_verifier() code_challenge = create_code_challenge(code_verifier) # OAuth endpoints given in the UNOS OAuth documentation authorization_url = "https://api.unos.org/login/v1/oauth2/authorize" token_url = "https://api.unos.org/login/v1/oauth2/token" # Client (application) credentials client_id = "" client_secret = "" callback_uri = "https://api.transplantpro.org/api/unos" # Update with your callback URI # Prepare headers auth_header = base64.b64encode(f'{client_id}:{client_secret}'.encode('utf-8')).decode('utf-8') headers = { 'Authorization': f'Basic {auth_header}', 'Content-Type': 'application/x-www-form-urlencoded' } # Prepare request data data = { 'grant_type': 'authorization_code', 'redirect_uri': callback_uri, 'code_verifier': code_verifier } @app.route('/') def index(): authorize_params = { 'response_type': 'code', 'client_id': client_id, 'redirect_uri': callback_uri, 'code_challenge': code_challenge, 'code_challenge_method': 'S256' } authorize_url = authorization_url + '?' + urlencode(authorize_params, quote_via=quote_plus) return redirect(authorize_url) @app.route('/callback') def callback(): authorization_code = request.args.get('code') data['code'] = authorization_code try: # Make the request to obtain access token response = requests.post(token_url, headers=headers, data=data) response.raise_for_status() # raise exception if invalid response auth_code = response.json() # Accessing the UNOS API api_url = 'https://api.unos.org/living-donor-tiedi/v1/donor-tiedi/v1/lookups/date-type' headers = {'Authorization': f'Bearer {auth_code["access_token"]}'} response = requests.get(api_url, headers=headers) response.raise_for_status() # raise exception if invalid response return response.json() except requests.exceptions.HTTPError as err: return f"HTTP Error occurred: {err.response.status_code} - {err.response.text}" except Exception as err: return f"An error occurred: {err}" if __name__ == '__main__': app.run()
报错截图:
API官方文档截图:
API文档参数说明:
- 请求授权码参数:response_type、client_id、redirect_uri、code_challenge
- 获取访问令牌参数:grant_type、code、redirect_uri、code_verifier
- 刷新令牌参数:access_token、token_type (Bearer)
内容的提问来源于stack exchange,提问作者NoobieDoobie365
相关产品推荐
相关产品推荐

