You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用passport-apple获取access token失败问题求助

使用passport-apple和Node.js实现Apple登录时出现InternalOAuthError问题

我是一名初级工程师,正在用passport-apple和Node.js开发苹果登录功能,持续收到错误:

{"name":"InternalOAuthError","message":"Failed to obtain access token","oauthError":{}}

具体现象:

  • AppleStrategy的回调函数完全没执行,没有任何日志输出,代码如下:
new AppleStrategy(
      {
        clientID: APPLE_AUTH.CLIENT_ID,
        teamID: APPLE_AUTH.TEAM_ID,
        callbackURL: APPLE_AUTH.LOGIN_CALLBACK_URL,
        keyID: APPLE_AUTH.KEY_ID,
        privateKeyLocation: 'config/AuthKey_Y8BG5JY7P3.p8',
        privateKeyString: APPLE_AUTH.privateKey,
        passReqToCallback: true,
      },
      function (accessToken, refreshToken, idToken, profile, cb) {
        try {
          // console.log(profile._json.email);
          // const socialLoginEmail = req.user.emails[0].value;
          // console.log(email);
          //화면에서 백으로
          // console.log(profile._json.email);
          // const user = await UserModelService.getUser(profile._json.email);
          // console.log(user);
          const idTokenDecoded = jwt.decode(idToken);
          // console.log('strategy', req);
          cb(null, idTokenDecoded);
        } catch (error) {
          console.error(error);
          // done(error);
        }
      },
    ),
  );
  • 但路由的回调函数有日志输出,这情况很奇怪,代码如下:
ROUTER.post('/apple/callback', function (req, res, next) {
  passport.authenticate('apple', function (err, user, info) {
    console.log('strategy', req);
    console.log('res 받기', res);
    console.log('user받기', user);
    console.log('info 받기', info);
    if (err) {
      if (err == 'AuthorizationError') {
        res.send(
          'Oops! Looks like you didn\'t allow the app to proceed. Please sign in again! <br /> \
                <a href="/login">Sign in with Apple</a>',
        );
      } else if (err == 'TokenError') {
        res.send(
          'Oops! Couldn\'t get a valid token from Apple\'s servers! <br /> \
                <a href="/login">Sign in with Apple</a>',
        );
      } else {
        res.send(err);
      }
    } else {
      if (req.body.user) {
        // Get the profile info (name and email) if the person is registering
        res.json({
          user: req.body.user,
          idToken: user,
        });
      } else {
        res.json(user);
      }
    }
  })(req, res, next);
});

已经卡了4天,求解决!


解决方案排查方向
  • 清理私钥配置冲突:不要同时设置privateKeyLocation和privateKeyString,二选一即可。用privateKeyString时要确保值是完整的PEM格式(包含首尾的-----BEGIN PRIVATE KEY-----和-----END PRIVATE KEY-----标记行);用文件路径则确认文件存在、路径正确且程序有读取权限。
  • 校准回调URL:Apple开发者后台配置的回调URL必须和代码中callbackURL完全一致,包括协议(HTTPS生产环境必填,localhost测试可使用HTTP)、端口、路径,任何细微差异都会导致token获取失败。
  • 修正Strategy回调参数顺序:开启passReqToCallback: true后,回调函数第一个参数必须是req,正确参数顺序为:
    function (req, accessToken, refreshToken, idToken, profile, cb) {
      // 此处可正常使用req
      const idTokenDecoded = jwt.decode(idToken);
      cb(null, idTokenDecoded);
    }
    
    原代码缺少req参数,会破坏passport的流程逻辑,甚至导致隐藏报错。
  • 开启调试日志:在代码入口添加process.env.DEBUG = 'passport-apple:*',运行时会输出OAuth流程的详细日志,能直接定位到获取token阶段的具体错误(比如签名无效、参数缺失)。
  • 检查依赖版本兼容性:确认jsonwebtoken和passport-apple的版本匹配,避免因依赖版本问题导致JWT签名/解码失败。

内容的提问来源于stack exchange,提问作者Taehwi Lee

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.01 04:46:48