You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

开发LTI工具时,如何用OAuth对XML格式POST请求签名?

Handling OAuth Signature for LTI Gradebook POX Requests

Great question! I’ve dealt with this exact confusion while building LTI gradebook integrations, so let me walk you through the correct approach here.

First, let’s clarify: when working with XML (POX) requests for LTI gradebooks, you don’t embed the oauth_signature (or any OAuth parameters) inside the XML payload itself. The LTI gradebook spec doesn’t define a schema field for OAuth data in the XML, and doing so would break the expected structure.

Instead, you’ll pass all OAuth parameters—including oauth_signature—via the HTTP Authorization header, following the OAuth 1.0a specification. This is the standard way to handle OAuth for non-form-encoded request bodies like XML, and it’s what LTI platforms expect for POX gradebook requests.

Here’s a step-by-step breakdown:

  1. Build your full XML payload exactly as specified in the LTI gradebook docs (no OAuth data included here). For example:

    <resultRecord>
      <sourcedId>user_123_course_456_assignment_789</sourcedId>
      <result>
        <score>0.85</score>
        <comment>Great work on the assignment!</comment>
      </result>
    </resultRecord>
    
  2. Generate the OAuth signature using the entire XML payload as part of the signature base string. Follow the OAuth 1.0a request body signing rules:

    • Include the full XML content in the request body component of the base string (properly URL-encoded per OAuth specs).
    • Use your consumer key/secret, nonce, timestamp, and HMAC-SHA1 (or the specified signature method) to compute oauth_signature.
  3. Construct the OAuth Authorization header with all required parameters. It should look something like this:

    OAuth oauth_consumer_key="your_consumer_key", oauth_nonce="random_unique_string", oauth_signature="your_generated_signature", oauth_signature_method="HMAC-SHA1", oauth_timestamp="1699999999", oauth_version="1.0"
    
  4. Send the POST request with:

    • Content-Type header set to application/xml
    • The Authorization header you built
    • Your XML payload as the request body

Why this works:

LTI platforms are designed to parse OAuth credentials from the Authorization header when dealing with non-form-encoded request bodies. Embedding OAuth data in the XML would violate both the LTI gradebook schema and OAuth 1.0a best practices for non-form payloads.

Content的提问来源于stack exchange,提问作者Justin Schultz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 08:10:09