SQL手动创建Simple OAuth令牌遇403权限错误排查
Drupal Simple OAuth手动创建令牌返回403问题排查
背景
我正在开发一个与Drupal数据库集成的Python服务,无法访问Drupal的/oauth2/token端点,需在Python中生成OAuth2访问令牌。现有两个访问令牌:
- 74127:通过Simple OAuth (OAuth2) & OpenID Connect Drupal模块创建
- 74145:通过SQL手动创建
数据库记录
Simple OAuth模块会创建oauth2_token和oauth2_token__scopes两张表,以下是两个令牌的数据库记录:
oauth2_token表记录
MySQL [db]> select * from oauth2_token where auth_user_id=189 and bundle='access_token'; +-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+ | id | bundle | uuid | auth_user_id | client | value | created | changed | expire | status | +-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+ | 74127 | access_token | 40d0a3cb-4eea-4553-a65c-aafef2f7457e | 189 | 1 | 799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28 | 1665143613 | 1665143613 | 1667562813 | 1 | | 74145 | access_token | ae63b832-2a1b-4545-9e91-c3554b922ce0 | 189 | 1 | b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313 | 1665158898 | 1665158898 | 1667562813 | 1 | +-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+
oauth2_token__scopes表记录
MySQL [db]> select * from oauth2_token__scopes where entity_id=74127 or entity_id=74145; +--------------+---------+-----------+-------------+----------+-------+------------------+ | bundle | deleted | entity_id | revision_id | langcode | delta | scopes_target_id | +--------------+---------+-----------+-------------+----------+-------+------------------+ | access_token | 0 | 74127 | 74127 | und | 0 | authenticated | | access_token | 0 | 74145 | 74145 | und | 0 | authenticated | +--------------+---------+-----------+-------------+----------+-------+------------------+
令牌详情与测试结果
74127(模块创建)
解码后的JWT头:
{ "alg": "RS256", "jti": "799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28", "typ": "JWT" }
JWT体:
{ "aud": "40d0a3cb-4eea-4553-a65c-aafef2f7457e", "jti": "799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28", "iat": 1665143613, "nbf": 1665143613, "exp": 1667562813, "sub": "189", "scope": [ "authenticated" ] }
使用该令牌访问受保护资源,返回200状态及资源内容。
74145(SQL手动创建)
采用相同格式生成的JWT头:
{ "alg": "RS256", "jti": "b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313", "typ": "JWT" }
JWT体:
{ "aud": "ae63b832-2a1b-4545-9e91-c3554b922ce0", "jti": "b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313", "iat": 1665143613, "nbf": 1665143613, "exp": 1667562813, "sub": "189", "scope": [ "authenticated" ] }
使用该令牌访问受保护资源时返回403状态:
{ "message": "The 'restful get digicel_user_details' permission is required." }
问题
既然两个令牌的数据库记录完全一致,为何74145会返回403错误?是否还需要其他记录来关联令牌与用户权限?
内容的提问来源于stack exchange,提问作者John Keyes
相关产品推荐
相关产品推荐

