GitLab OAuth Refresh Token过期咨询:无法刷新令牌的原因排查
GitLab OAuth刷新令牌一周后突然失效的原因排查
场景说明
- 我在Web应用中集成了GitLab OAuth功能,用户通过Access Token授权应用访问其GitLab仓库
- 用户完成仓库关联后,应用会将Refresh Token和Access Token存入数据库,同时通过每2小时执行一次的cron任务刷新令牌(GitLab Access Token有效期为2小时)
- 刷新令牌使用的GitLab API地址:
https://gitlab.com/oauth/token?client_id={}&client_secret={}&refresh_token={}&grant_type=refresh_token&redirect_uri={}
问题描述
cron任务正常运行一周后突然失败,导致应用失去与用户仓库的连接,GitLab API返回错误信息:
The provided authorization grant is invalid, expired, revoked, does not match the redirection URI used in the authorization request, or was issued to another client.
由于任务前期运行正常,我确认client_id、client_secret、refresh_token、redirect_uri这些参数均无问题,目前只能让用户重新授权关联仓库。
已排除的原因
- 排除刷新频率过高的问题:测试发现即使每日调用12次刷新接口,也不会出现异常
- 排除Access Token有效时刷新导致的问题:使用过期Access Token拉取仓库后,仍能成功调用刷新接口获取新令牌
求助需求
我需要明确导致Refresh Token过期、无法继续刷新的根本原因,查阅GitLab官方API文档后未找到相关线索。
内容的提问来源于stack exchange,提问作者umer
相关产品推荐
相关产品推荐

