You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

ConstantContact V3 获取访问令牌时出现400错误

解决ConstantContact V3 API令牌请求400 Bad Request问题

我们按照ConstantContact V3 API官方文档实现授权流程,生成授权URL的步骤正常,能成功获取授权码,但用授权码请求访问令牌时,持续收到Cloudflare返回的400 Bad Request错误。

现有代码

生成授权URL的代码

$baseURL = "https://authz.constantcontact.com/oauth2/default/v1/authorize";
$authURL = $baseURL . "?client_id=" . $this->_clientID . "&response_type=code&scope=".urlencode('offline_access')."&state=" . $this->user->info['id'] . "&redirect_uri=" . urlencode(DOMAIN.'connect/constantcontact/'); 

请求令牌的代码

// Use cURL to get access token and refresh token
$ch = curl_init();

// Define base URL
$base = 'https://authz.constantcontact.com/oauth2/default/v1/token';

// Create full request URL
$url = $base . '?code=' . $_GET['code'] . '&redirect_uri=' . urlencode(DOMAIN.'connect/constantcontact/') . '&grant_type=authorization_code';
//echo $url;
curl_setopt($ch, CURLOPT_URL, $url);

// Set authorization header
// Make string of "API_KEY:SECRET"
$auth = $this->_clientID . ':' . $this->_clientSecret;
//echo $auth;
// Base64 encode it
$credentials = base64_encode($auth);
// Create and set the Authorization header to use the encoded credentials, and set the Content-Type header
$authorization = 'Authorization: Basic ' . $credentials;
curl_setopt($ch, CURLOPT_HTTPHEADER, array($authorization, 'Accept: application/json', 'Content-Type: application/x-www-form-urlencoded'));

// Set method and to expect response
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);

// Make the call
$result = curl_exec($ch);
curl_close($ch);

错误响应

<html>
<head><title>400 Bad Request</title></head>
<body>
<center><h1>400 Bad Request</h1></center>
<hr><center>cloudflare</center>
</body>
</html>

排查与解决建议

  • 修正请求参数传递方式:
    OAuth2令牌请求要求code、redirect_uri、grant_type必须放在POST请求体中,而非URL查询参数。当前代码的参数传递方式不符合规范,会被判定为无效请求。修正后的代码示例:

    $ch = curl_init();
    $base = 'https://authz.constantcontact.com/oauth2/default/v1/token';
    
    // 将参数放入POST请求体
    $postData = http_build_query([
        'code' => $_GET['code'],
        'redirect_uri' => DOMAIN.'connect/constantcontact/',
        'grant_type' => 'authorization_code'
    ]);
    
    curl_setopt($ch, CURLOPT_URL, $base);
    curl_setopt($ch, CURLOPT_POSTFIELDS, $postData);
    
    $auth = $this->_clientID . ':' . $this->_clientSecret;
    $credentials = base64_encode($auth);
    $authorization = 'Authorization: Basic ' . $credentials;
    curl_setopt($ch, CURLOPT_HTTPHEADER, array($authorization, 'Accept: application/json', 'Content-Type: application/x-www-form-urlencoded'));
    
    curl_setopt($ch, CURLOPT_POST, true);
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
    
    $result = curl_exec($ch);
    curl_close($ch);
    
  • 严格校验redirect_uri一致性:
    确保请求令牌时的redirect_uri与生成授权URL时的字符串完全一致,包括末尾斜杠、域名大小写等细节。ConstantContact的OAuth2服务器会严格校验该参数,不匹配直接返回错误。

  • 验证Base64凭证合法性:
    确认$this->_clientID和$this->_clientSecret无换行、空格或特殊字符,拼接后再进行Base64编码。可临时输出$credentials的值,在线验证编码是否正确(注意不要泄露真实凭证)。

  • 添加cURL错误调试:
    在curl_exec后增加错误捕获逻辑,定位具体请求问题:

    $result = curl_exec($ch);
    if(curl_errno($ch)){
        echo 'Curl error: ' . curl_error($ch);
    }
    curl_close($ch);
    
  • 排查Cloudflare拦截:
    若上述修正后仍报错,可能是服务器出站IP被Cloudflare的WAF拦截。可尝试在服务器上用curl命令行直接测试令牌请求,或检查服务器IP是否在ConstantContact的IP白名单中(若有设置)。

内容的提问来源于stack exchange,提问作者Clint C.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.31 15:21:02