You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SQL手动创建Simple OAuth令牌遇403权限错误排查

Drupal Simple OAuth手动创建令牌返回403问题排查

背景

我正在开发一个与Drupal数据库集成的Python服务,无法访问Drupal的/oauth2/token端点,需在Python中生成OAuth2访问令牌。现有两个访问令牌:

  • 74127:通过Simple OAuth (OAuth2) & OpenID Connect Drupal模块创建
  • 74145:通过SQL手动创建

数据库记录

Simple OAuth模块会创建oauth2_token和oauth2_token__scopes两张表,以下是两个令牌的数据库记录:

oauth2_token表记录

MySQL [db]> select * from oauth2_token where auth_user_id=189 and bundle='access_token';
+-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+
| id    | bundle       | uuid                                 | auth_user_id | client | value                                                                            | created    | changed    | expire     | status |
+-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+
| 74127 | access_token | 40d0a3cb-4eea-4553-a65c-aafef2f7457e |          189 |      1 | 799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28 | 1665143613 | 1665143613 | 1667562813 |      1 |
| 74145 | access_token | ae63b832-2a1b-4545-9e91-c3554b922ce0 |          189 |      1 | b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313 | 1665158898 | 1665158898 | 1667562813 |      1 |
+-------+--------------+--------------------------------------+--------------+--------+----------------------------------------------------------------------------------+------------+------------+------------+--------+

oauth2_token__scopes表记录

MySQL [db]> select * from oauth2_token__scopes where entity_id=74127 or entity_id=74145;
+--------------+---------+-----------+-------------+----------+-------+------------------+
| bundle       | deleted | entity_id | revision_id | langcode | delta | scopes_target_id |
+--------------+---------+-----------+-------------+----------+-------+------------------+
| access_token |       0 |    74127  |       74127 | und      |     0 | authenticated    |
| access_token |       0 |    74145  |       74145 | und      |     0 | authenticated    |
+--------------+---------+-----------+-------------+----------+-------+------------------+

令牌详情与测试结果

74127(模块创建)

解码后的JWT头:

{
  "alg": "RS256",
  "jti": "799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28",
  "typ": "JWT"
}

JWT体:

{
  "aud": "40d0a3cb-4eea-4553-a65c-aafef2f7457e",
  "jti": "799b6f294d777f17f74b00c0c06c2889a2082db4193fa099bef19445e9ddb14159ca655db34feb28",
  "iat": 1665143613,
  "nbf": 1665143613,
  "exp": 1667562813,
  "sub": "189",
  "scope": [
    "authenticated"
  ]
}

使用该令牌访问受保护资源,返回200状态及资源内容。

74145(SQL手动创建)

采用相同格式生成的JWT头:

{
  "alg": "RS256",
  "jti": "b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313",
  "typ": "JWT"
}

JWT体:

{
  "aud": "ae63b832-2a1b-4545-9e91-c3554b922ce0",
  "jti": "b03fd9a699030a37c97b097c8365537023dcd0faf2828f2761b2b9b61847cf10446134c185c10313",
  "iat": 1665143613,
  "nbf": 1665143613,
  "exp": 1667562813,
  "sub": "189",
  "scope": [
    "authenticated"
  ]
}

使用该令牌访问受保护资源时返回403状态:

{
    "message": "The 'restful get digicel_user_details' permission is required."
}

问题

既然两个令牌的数据库记录完全一致,为何74145会返回403错误?是否还需要其他记录来关联令牌与用户权限?


内容的提问来源于stack exchange,提问作者John Keyes

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.17 04:00:37