Django应用Github登录触发AuthCanceled错误,求助排查原因
我在开发一个Django应用,尝试通过Github登录时遇到了如下错误:
AuthCanceled at /oauth/complete/github/ Authentication process canceled Request Method: GET Request URL: https://my-site.com/oauth/complete/github/?code=xxxxxxxxxxxxxx&state=xxxxxxxxxxxxxx Django Version: 3.0.5 Exception Type: AuthCanceled Exception Value: Authentication process canceled Exception Location: /usr/local/lib/python3.7/site-packages/social_core/utils.py in wrapper, line 254 Python Executable: /usr/local/bin/python Python Version: 3.7.2 Python Path: ['/code', '/usr/local/bin', '/usr/local/lib/python37.zip', '/usr/local/lib/python3.7', '/usr/local/lib/python3.7/lib-dynload', '/usr/local/lib/python3.7/site-packages']
我已经在settings.py中配置了SOCIAL_AUTH_GITHUB_KEY和SOCIAL_AUTH_GITHUB_SECRET,并且在Github应用设置里添加了https://my-site.com/oauth/作为授权回调URL。
补充说明
之所以使用/oauth/complete/github这个路径,是因为之前遇到过URL匹配错误,当时的错误信息如下:
Using the URLconf defined in my-site.urls, Django tried these URL patterns, in this order: 1. home/ 2. login/ [name='login'] 3. logout/ [name='logout'] 4. oauth/ ...
可能的问题及解决方法
回调URL不匹配
Github应用设置里的回调URL必须与Django中social-auth的回调路径完全一致。social-auth的默认Github回调路径是/oauth/complete/github/(注意末尾斜杠),而不是你当前设置的https://my-site.com/oauth/。请在Github应用的授权回调URL中填写完整路径https://my-site.com/oauth/complete/github/。Session验证失败
AuthCanceled错误常与OAuth的state参数验证失败相关,大概率是Session在跳转过程中丢失:- 检查
settings.py中的SESSION_COOKIE_DOMAIN是否与站点域名一致; - 确保
SESSION_COOKIE_SECURE = True(因站点使用HTTPS,避免Session Cookie明文传输丢失); - 若使用容器或反向代理,需配置
SECURE_PROXY_SSL_HEADER让Django识别HTTPS请求:SECURE_PROXY_SSL_HEADER = ('HTTP_X_FORWARDED_PROTO', 'https')
- 检查
URLconf路由配置错误
从你补充的URL匹配错误来看,oauth/路由未正确包含social-auth的子路由。请检查urls.py的配置:from django.urls import path, include urlpatterns = [ # 其他已有路由 path('oauth/', include('social_django.urls', namespace='social')), ]这样配置后,
/oauth/complete/github/会被自动匹配,无需手动指定路径。用户主动取消授权
如果用户在Github的授权页面点击了取消,也会触发该错误。这种情况属于用户主动操作,可在前端添加相应提示说明。
内容的提问来源于stack exchange,提问作者Palinuro

