ConstantContact V3 获取访问令牌时出现400错误
解决ConstantContact V3 API令牌请求400 Bad Request问题
我们按照ConstantContact V3 API官方文档实现授权流程,生成授权URL的步骤正常,能成功获取授权码,但用授权码请求访问令牌时,持续收到Cloudflare返回的400 Bad Request错误。
现有代码
生成授权URL的代码
$baseURL = "https://authz.constantcontact.com/oauth2/default/v1/authorize"; $authURL = $baseURL . "?client_id=" . $this->_clientID . "&response_type=code&scope=".urlencode('offline_access')."&state=" . $this->user->info['id'] . "&redirect_uri=" . urlencode(DOMAIN.'connect/constantcontact/');
请求令牌的代码
// Use cURL to get access token and refresh token $ch = curl_init(); // Define base URL $base = 'https://authz.constantcontact.com/oauth2/default/v1/token'; // Create full request URL $url = $base . '?code=' . $_GET['code'] . '&redirect_uri=' . urlencode(DOMAIN.'connect/constantcontact/') . '&grant_type=authorization_code'; //echo $url; curl_setopt($ch, CURLOPT_URL, $url); // Set authorization header // Make string of "API_KEY:SECRET" $auth = $this->_clientID . ':' . $this->_clientSecret; //echo $auth; // Base64 encode it $credentials = base64_encode($auth); // Create and set the Authorization header to use the encoded credentials, and set the Content-Type header $authorization = 'Authorization: Basic ' . $credentials; curl_setopt($ch, CURLOPT_HTTPHEADER, array($authorization, 'Accept: application/json', 'Content-Type: application/x-www-form-urlencoded')); // Set method and to expect response curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // Make the call $result = curl_exec($ch); curl_close($ch);
错误响应
<html> <head><title>400 Bad Request</title></head> <body> <center><h1>400 Bad Request</h1></center> <hr><center>cloudflare</center> </body> </html>
排查与解决建议
修正请求参数传递方式:
OAuth2令牌请求要求code、redirect_uri、grant_type必须放在POST请求体中,而非URL查询参数。当前代码的参数传递方式不符合规范,会被判定为无效请求。修正后的代码示例:$ch = curl_init(); $base = 'https://authz.constantcontact.com/oauth2/default/v1/token'; // 将参数放入POST请求体 $postData = http_build_query([ 'code' => $_GET['code'], 'redirect_uri' => DOMAIN.'connect/constantcontact/', 'grant_type' => 'authorization_code' ]); curl_setopt($ch, CURLOPT_URL, $base); curl_setopt($ch, CURLOPT_POSTFIELDS, $postData); $auth = $this->_clientID . ':' . $this->_clientSecret; $credentials = base64_encode($auth); $authorization = 'Authorization: Basic ' . $credentials; curl_setopt($ch, CURLOPT_HTTPHEADER, array($authorization, 'Accept: application/json', 'Content-Type: application/x-www-form-urlencoded')); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); $result = curl_exec($ch); curl_close($ch);严格校验redirect_uri一致性:
确保请求令牌时的redirect_uri与生成授权URL时的字符串完全一致,包括末尾斜杠、域名大小写等细节。ConstantContact的OAuth2服务器会严格校验该参数,不匹配直接返回错误。验证Base64凭证合法性:
确认$this->_clientID和$this->_clientSecret无换行、空格或特殊字符,拼接后再进行Base64编码。可临时输出$credentials的值,在线验证编码是否正确(注意不要泄露真实凭证)。添加cURL错误调试:
在curl_exec后增加错误捕获逻辑,定位具体请求问题:$result = curl_exec($ch); if(curl_errno($ch)){ echo 'Curl error: ' . curl_error($ch); } curl_close($ch);排查Cloudflare拦截:
若上述修正后仍报错,可能是服务器出站IP被Cloudflare的WAF拦截。可尝试在服务器上用curl命令行直接测试令牌请求,或检查服务器IP是否在ConstantContact的IP白名单中(若有设置)。
内容的提问来源于stack exchange,提问作者Clint C.
相关产品推荐
相关产品推荐

