You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Django中JWT社交登录问题:授权码已过期求助

Fixing Expired Authorization Code for JWT Social Login in Django

Hey there! Let's break down what's causing that expired authorization code error and get your social login flow working smoothly.

First, Understand Why the Code Expires

Facebook (and most other social platforms) issues short-lived, one-time use authorization codes—they typically expire within a few minutes, and you can't reuse them. If you're manually copying the code from your browser and pasting it into a request later, that's almost certainly why you're seeing the OAuthException: This authorization code has expired error.

Step-by-Step Fixes

1. Ensure redirect_uri Matches Exactly Everywhere

This is the most common pitfall for OAuth errors:

  • The redirect_uri you use when generating the Facebook authorization URL must be identical to the one you set in your Facebook Developer Dashboard (under "Valid OAuth Redirect URIs") and the one you send to your Django JWT endpoint.
  • Even tiny differences (like http vs https, a trailing slash, or a typo in the domain) will cause the code to be rejected or marked as invalid.

2. Use the Code Immediately (Automate the Flow)

Stop manually copying codes—build a callback flow to capture the code and send it to your Django endpoint instantly. Here's a quick example of a temporary Django view to test this:

from django.http import JsonResponse
import requests

def facebook_callback(request):
    # Capture the code from Facebook's redirect
    auth_code = request.GET.get('code')
    if not auth_code:
        return JsonResponse({'error': 'No authorization code received'}, status=400)
    
    # Send the fresh code directly to your JWT endpoint
    payload = {
        'provider': 'facebook',
        'code': auth_code,
        'redirect_uri': 'https://your-domain.com/facebook/callback'  # Match this everywhere!
    }
    
    jwt_response = requests.post('http://your-django-api.com/api/login/social/jwt/', data=payload)
    return JsonResponse(jwt_response.json())

Add this view to your urls.py, update your Facebook Developer Dashboard with the callback URL, then test the full flow by visiting Facebook's authorization link—this ensures the code is used before it expires.

3. Verify Your Django Social Auth Configuration

If you're using a library like django-rest-framework-social-oauth2, double-check these settings in settings.py:

# Facebook OAuth settings
SOCIAL_AUTH_FACEBOOK_KEY = 'your-facebook-app-id'
SOCIAL_AUTH_FACEBOOK_SECRET = 'your-facebook-app-secret'
SOCIAL_AUTH_FACEBOOK_SCOPE = ['email']  # Required for user data access
SOCIAL_AUTH_FACEBOOK_REDIRECT_URI = 'https://your-domain.com/facebook/callback'  # Match this!

Also, make sure you're using the latest stable version of your social auth library—older versions may have bugs related to code validation.

4. Notes for Twitter & Google

  • Twitter: Uses OAuth 1.0a instead of OAuth 2.0 (by default), so the code flow works differently. Confirm your library supports Twitter's auth method, and double-check your API key/secret and callback URL.
  • Google: Like Facebook, requires an exact redirect_uri match, and authorization codes are short-lived/one-time use. Follow the same automated callback flow as above.

Quick Troubleshooting Checklist

  • Did I use the code within 5-10 minutes of receiving it?
  • Is my redirect_uri identical in the authorization URL, Facebook dashboard, and Django request?
  • Are my Facebook app ID/secret correctly configured in Django?
  • Am I reusing a code that's already been used once?

内容的提问来源于stack exchange,提问作者RaHul KasHyap

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.13 08:47:04