使用passport-apple获取access token失败问题求助
使用passport-apple和Node.js实现Apple登录时出现InternalOAuthError问题
我是一名初级工程师,正在用passport-apple和Node.js开发苹果登录功能,持续收到错误:
{"name":"InternalOAuthError","message":"Failed to obtain access token","oauthError":{}}
具体现象:
- AppleStrategy的回调函数完全没执行,没有任何日志输出,代码如下:
new AppleStrategy( { clientID: APPLE_AUTH.CLIENT_ID, teamID: APPLE_AUTH.TEAM_ID, callbackURL: APPLE_AUTH.LOGIN_CALLBACK_URL, keyID: APPLE_AUTH.KEY_ID, privateKeyLocation: 'config/AuthKey_Y8BG5JY7P3.p8', privateKeyString: APPLE_AUTH.privateKey, passReqToCallback: true, }, function (accessToken, refreshToken, idToken, profile, cb) { try { // console.log(profile._json.email); // const socialLoginEmail = req.user.emails[0].value; // console.log(email); //화면에서 백으로 // console.log(profile._json.email); // const user = await UserModelService.getUser(profile._json.email); // console.log(user); const idTokenDecoded = jwt.decode(idToken); // console.log('strategy', req); cb(null, idTokenDecoded); } catch (error) { console.error(error); // done(error); } }, ), );
- 但路由的回调函数有日志输出,这情况很奇怪,代码如下:
ROUTER.post('/apple/callback', function (req, res, next) { passport.authenticate('apple', function (err, user, info) { console.log('strategy', req); console.log('res 받기', res); console.log('user받기', user); console.log('info 받기', info); if (err) { if (err == 'AuthorizationError') { res.send( 'Oops! Looks like you didn\'t allow the app to proceed. Please sign in again! <br /> \ <a href="/login">Sign in with Apple</a>', ); } else if (err == 'TokenError') { res.send( 'Oops! Couldn\'t get a valid token from Apple\'s servers! <br /> \ <a href="/login">Sign in with Apple</a>', ); } else { res.send(err); } } else { if (req.body.user) { // Get the profile info (name and email) if the person is registering res.json({ user: req.body.user, idToken: user, }); } else { res.json(user); } } })(req, res, next); });
已经卡了4天,求解决!
解决方案排查方向
- 清理私钥配置冲突:不要同时设置
privateKeyLocation和privateKeyString,二选一即可。用privateKeyString时要确保值是完整的PEM格式(包含首尾的-----BEGIN PRIVATE KEY-----和-----END PRIVATE KEY-----标记行);用文件路径则确认文件存在、路径正确且程序有读取权限。 - 校准回调URL:Apple开发者后台配置的回调URL必须和代码中
callbackURL完全一致,包括协议(HTTPS生产环境必填,localhost测试可使用HTTP)、端口、路径,任何细微差异都会导致token获取失败。 - 修正Strategy回调参数顺序:开启
passReqToCallback: true后,回调函数第一个参数必须是req,正确参数顺序为:
原代码缺少function (req, accessToken, refreshToken, idToken, profile, cb) { // 此处可正常使用req const idTokenDecoded = jwt.decode(idToken); cb(null, idTokenDecoded); }req参数,会破坏passport的流程逻辑,甚至导致隐藏报错。 - 开启调试日志:在代码入口添加
process.env.DEBUG = 'passport-apple:*',运行时会输出OAuth流程的详细日志,能直接定位到获取token阶段的具体错误(比如签名无效、参数缺失)。 - 检查依赖版本兼容性:确认
jsonwebtoken和passport-apple的版本匹配,避免因依赖版本问题导致JWT签名/解码失败。
内容的提问来源于stack exchange,提问作者Taehwi Lee
相关产品推荐
相关产品推荐

