Django中JWT社交登录问题:授权码已过期求助
Hey there! Let's break down what's causing that expired authorization code error and get your social login flow working smoothly.
First, Understand Why the Code Expires
Facebook (and most other social platforms) issues short-lived, one-time use authorization codes—they typically expire within a few minutes, and you can't reuse them. If you're manually copying the code from your browser and pasting it into a request later, that's almost certainly why you're seeing the OAuthException: This authorization code has expired error.
Step-by-Step Fixes
1. Ensure redirect_uri Matches Exactly Everywhere
This is the most common pitfall for OAuth errors:
- The
redirect_uriyou use when generating the Facebook authorization URL must be identical to the one you set in your Facebook Developer Dashboard (under "Valid OAuth Redirect URIs") and the one you send to your Django JWT endpoint. - Even tiny differences (like
httpvshttps, a trailing slash, or a typo in the domain) will cause the code to be rejected or marked as invalid.
2. Use the Code Immediately (Automate the Flow)
Stop manually copying codes—build a callback flow to capture the code and send it to your Django endpoint instantly. Here's a quick example of a temporary Django view to test this:
from django.http import JsonResponse import requests def facebook_callback(request): # Capture the code from Facebook's redirect auth_code = request.GET.get('code') if not auth_code: return JsonResponse({'error': 'No authorization code received'}, status=400) # Send the fresh code directly to your JWT endpoint payload = { 'provider': 'facebook', 'code': auth_code, 'redirect_uri': 'https://your-domain.com/facebook/callback' # Match this everywhere! } jwt_response = requests.post('http://your-django-api.com/api/login/social/jwt/', data=payload) return JsonResponse(jwt_response.json())
Add this view to your urls.py, update your Facebook Developer Dashboard with the callback URL, then test the full flow by visiting Facebook's authorization link—this ensures the code is used before it expires.
3. Verify Your Django Social Auth Configuration
If you're using a library like django-rest-framework-social-oauth2, double-check these settings in settings.py:
# Facebook OAuth settings SOCIAL_AUTH_FACEBOOK_KEY = 'your-facebook-app-id' SOCIAL_AUTH_FACEBOOK_SECRET = 'your-facebook-app-secret' SOCIAL_AUTH_FACEBOOK_SCOPE = ['email'] # Required for user data access SOCIAL_AUTH_FACEBOOK_REDIRECT_URI = 'https://your-domain.com/facebook/callback' # Match this!
Also, make sure you're using the latest stable version of your social auth library—older versions may have bugs related to code validation.
4. Notes for Twitter & Google
- Twitter: Uses OAuth 1.0a instead of OAuth 2.0 (by default), so the code flow works differently. Confirm your library supports Twitter's auth method, and double-check your API key/secret and callback URL.
- Google: Like Facebook, requires an exact
redirect_urimatch, and authorization codes are short-lived/one-time use. Follow the same automated callback flow as above.
Quick Troubleshooting Checklist
- Did I use the code within 5-10 minutes of receiving it?
- Is my
redirect_uriidentical in the authorization URL, Facebook dashboard, and Django request? - Are my Facebook app ID/secret correctly configured in Django?
- Am I reusing a code that's already been used once?
内容的提问来源于stack exchange,提问作者RaHul KasHyap

