Verdaccio对接Bitbucket遇Error 400,请求技术协助
Hey Fabien, sorry you’ve been stuck on this frustrating 400 error for 4 days—let’s break down the most likely culprits and fixes to get your integration working.
First, let’s recap what you’ve tried so far: modifying your config.yaml, replacing @ in your username with .., but still hitting the same 400 error when trying to log in. Below are actionable steps to diagnose and fix this:
1. Double-Check Your Bitbucket OAuth App Setup
This is where most 400 errors start:
- Callback URL Match: Ensure the callback URL in your Bitbucket OAuth app exactly matches the
callbackURLin your Verdaccio config. For example, if Verdaccio runs athttp://localhost:4873, the callback URL must behttp://localhost:4873/api/auth/bitbucket/callback—no extra slashes, no HTTPS/HTTP mismatch, no typos. - Required Permissions: Make sure your Bitbucket app has the
account:readpermission enabled (this is the minimum needed to verify user identities). - Client Credentials: Confirm your
clientIdandclientSecretare copied correctly—even a single missing character or extra space will cause a 400.
2. Audit Your Verdaccio config.yaml Bitbucket Section
Here’s a clean, working example for reference (adjust to your environment):
auth: bitbucket: clientId: "YOUR_BITBUCKET_CLIENT_ID" clientSecret: "YOUR_BITBUCKET_CLIENT_SECRET" callbackURL: "http://your-verdaccio-domain:4873/api/auth/bitbucket/callback" # Uncomment this ONLY if you're using Bitbucket Server (not Cloud) # baseURL: "https://your-bitbucket-server-url/rest/api/1.0"
- Key Note: You shouldn’t need to replace
@in your username manually—the Verdaccio Bitbucket plugin handles email-formatted usernames automatically. Reverting to your original username might fix unexpected mismatches during authentication. - Bitbucket Server vs Cloud: If you’re using self-hosted Bitbucket Server, the
baseURLis mandatory. Omit it entirely for Bitbucket Cloud.
3. Dig Into the Log Details for Specific 400 Context
Your full logs hold the key here—look for the exact error message tied to the 400 response. Common scenarios:
- If you see
invalid_requestwithInvalid redirect_uri, your callback URL is definitely misconfigured. invalid_clientpoints to wrongclientId/clientSecret.missing_scopemeans your Bitbucket app lacks the necessary permissions.
For example, a log line like this is a clear red flag:
error: [bitbucket] Error exchanging code for token: 400 Bad Request, response: {"error": "invalid_request", "error_description": "Invalid redirect_uri"}
4. Rule Out Network/CORS Interference
- Proxy/Firewall: If Verdaccio is behind a proxy or firewall, ensure it can reach Bitbucket’s API endpoints (Cloud:
https://bitbucket.organdhttps://api.bitbucket.org; Server: your self-hosted URL). - CORS Settings: Verify your Verdaccio CORS config allows your domain:
server: cors: origin: ["http://your-verdaccio-domain:4873"] methods: ["GET", "PUT", "POST", "DELETE", "PATCH"]
5. Test with a Minimal Config
Strip down your config.yaml to only the essential settings (Bitbucket auth, basic server setup) and remove any extra plugins or complex permission rules. Restart Verdaccio and try logging in again—this will rule out conflicts from other configs.
If none of these steps fix the issue, share the specific 400 error snippet from your logs, and we can narrow it down further!
内容的提问来源于stack exchange,提问作者FabienC

