You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

.NET Core重写OAuth2令牌端点请求及Ebay OAuth2报错排查

解决.NET Core 2中Ebay OAuth2令牌请求BadRequest问题 + 重写令牌请求指南

看起来你卡在了Ebay OAuth2流程的最后一步,授权成功但拿令牌失败的BadRequest确实很让人头疼,我帮你拆解下问题,同时手把手教你怎么重写.NET Core的OAuth令牌请求。

先排查令牌请求失败的核心原因

你收到的invalid_request错误,90%以上是因为请求格式/参数不符合Ebay的OAuth2要求,先从这几个关键点检查:

  1. 必填参数是否完整且一致:Ebay令牌请求必须包含code(授权码)、client_id、client_secret、grant_type=authorization_code、redirect_uri,而且redirect_uri必须和你发起授权请求时用的完全一致(包括大小写、末尾斜杠这类细节)。
  2. 请求内容类型错误:Ebay要求令牌请求必须用application/x-www-form-urlencoded格式,但.NET Core默认的OAuth中间件可能会用JSON格式发送请求,这是最常见的坑。
  3. Client凭证传递方式:Ebay支持两种方式传递Client ID和Secret——要么放在表单参数里,要么用Basic Auth(把client_id:client_secret转Base64后放在Authorization头里),如果方式不对也会报错。

在.NET Core 2中重写OAuth2令牌端点请求

要解决这个问题,我们需要通过自定义OAuthEvents来完全控制令牌请求的格式和内容,具体代码如下(直接放到Startup.cs的ConfigureServices方法里):

using System.Net.Http.Headers;
using System.Text;
using Microsoft.AspNetCore.Authentication.Cookies;
using Microsoft.AspNetCore.Authentication.OAuth;

// ...其他服务配置...

services.AddAuthentication(options =>
{
    options.DefaultAuthenticateScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultSignInScheme = CookieAuthenticationDefaults.AuthenticationScheme;
    options.DefaultChallengeScheme = "Ebay";
})
.AddCookie()
.AddOAuth("Ebay", options =>
{
    // 替换成你的Ebay开发者凭证
    options.ClientId = "你的Ebay Client ID";
    options.ClientSecret = "你的Ebay Client Secret";
    // 回调地址必须和Ebay开发者后台配置的一致
    options.CallbackPath = new PathString("/signin-ebay");
    // 注意区分沙箱和生产环境的端点
    options.AuthorizationEndpoint = "https://auth.ebay.com/oauth2/authorize"; // 生产环境
    // options.AuthorizationEndpoint = "https://auth.sandbox.ebay.com/oauth2/authorize"; // 沙箱环境
    options.TokenEndpoint = "https://api.ebay.com/identity/v1/oauth2/token"; // 生产环境
    // options.TokenEndpoint = "https://api.sandbox.ebay.com/identity/v1/oauth2/token"; // 沙箱环境
    options.UserInformationEndpoint = "https://api.ebay.com/identity/v1/user/profile";

    // 核心:重写令牌请求的生成逻辑
    options.Events = new OAuthEvents
    {
        // 自定义令牌请求的内容和格式
        OnCreatingTokenRequest = context =>
        {
            // 清空默认的JSON请求内容,改用表单格式
            context.TokenRequest.Content = new FormUrlEncodedContent(new Dictionary<string, string>
            {
                ["grant_type"] = "authorization_code",
                ["code"] = context.Code,
                ["redirect_uri"] = context.RedirectUri,
                ["client_id"] = options.ClientId,
                ["client_secret"] = options.ClientSecret
            });
            
            // 设置Ebay要求的Content-Type
            context.TokenRequest.Content.Headers.ContentType = new MediaTypeHeaderValue("application/x-www-form-urlencoded");

            // 如果你想用Basic Auth方式传递凭证,可以注释上面的client_id/client_secret参数,改用下面的代码
            // var credentials = Convert.ToBase64String(Encoding.UTF8.GetBytes($"{options.ClientId}:{options.ClientSecret}"));
            // context.TokenRequest.Headers.Authorization = new AuthenticationHeaderValue("Basic", credentials);

            return Task.CompletedTask;
        },
        // 可选:处理令牌响应后的逻辑(比如解析用户信息)
        OnCreatingTicket = async context =>
        {
            // 这里可以调用Ebay的用户信息接口获取用户数据,示例:
            var request = new HttpRequestMessage(HttpMethod.Get, context.Options.UserInformationEndpoint);
            request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", context.AccessToken);
            var response = await context.Backchannel.SendAsync(request, context.HttpContext.RequestAborted);
            response.EnsureSuccessStatusCode();
            var userData = await response.Content.ReadAsStringAsync();
            
            // 将用户数据添加到Claims中
            var claims = JsonDocument.Parse(userData).RootElement;
            context.Identity.AddClaim(new Claim("ebay_user_id", claims.GetProperty("userId").GetString()));
        }
    };
});

代码说明

  • 通过OnCreatingTokenRequest事件,我们完全接管了令牌请求的生成过程,把默认的JSON格式改成了Ebay要求的表单格式。
  • 确保所有必填参数都正确传递,尤其是redirect_uri要和授权时完全一致。
  • 可以根据需求选择用表单参数还是Basic Auth传递Client凭证,两种方式Ebay都支持。

验证请求正确性

如果还是不确定问题,可以用Postman手动模拟令牌请求:

  1. POST请求到对应环境的令牌端点
  2. 设置Content-Type为application/x-www-form-urlencoded
  3. 填入所有必填参数,发送请求
    如果手动请求能成功,说明你的中间件配置没问题;如果手动也失败,那就要检查你的Client凭证、授权码或者回调地址是否正确了。

内容的提问来源于stack exchange,提问作者Bella Gelb

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:29:27