开发LTI工具时,如何用OAuth对XML格式POST请求签名?
Great question! I’ve dealt with this exact confusion while building LTI gradebook integrations, so let me walk you through the correct approach here.
First, let’s clarify: when working with XML (POX) requests for LTI gradebooks, you don’t embed the oauth_signature (or any OAuth parameters) inside the XML payload itself. The LTI gradebook spec doesn’t define a schema field for OAuth data in the XML, and doing so would break the expected structure.
Instead, you’ll pass all OAuth parameters—including oauth_signature—via the HTTP Authorization header, following the OAuth 1.0a specification. This is the standard way to handle OAuth for non-form-encoded request bodies like XML, and it’s what LTI platforms expect for POX gradebook requests.
Here’s a step-by-step breakdown:
Build your full XML payload exactly as specified in the LTI gradebook docs (no OAuth data included here). For example:
<resultRecord> <sourcedId>user_123_course_456_assignment_789</sourcedId> <result> <score>0.85</score> <comment>Great work on the assignment!</comment> </result> </resultRecord>Generate the OAuth signature using the entire XML payload as part of the signature base string. Follow the OAuth 1.0a request body signing rules:
- Include the full XML content in the request body component of the base string (properly URL-encoded per OAuth specs).
- Use your consumer key/secret, nonce, timestamp, and HMAC-SHA1 (or the specified signature method) to compute
oauth_signature.
Construct the OAuth Authorization header with all required parameters. It should look something like this:
OAuth oauth_consumer_key="your_consumer_key", oauth_nonce="random_unique_string", oauth_signature="your_generated_signature", oauth_signature_method="HMAC-SHA1", oauth_timestamp="1699999999", oauth_version="1.0"Send the POST request with:
Content-Typeheader set toapplication/xml- The
Authorizationheader you built - Your XML payload as the request body
Why this works:
LTI platforms are designed to parse OAuth credentials from the Authorization header when dealing with non-form-encoded request bodies. Embedding OAuth data in the XML would violate both the LTI gradebook schema and OAuth 1.0a best practices for non-form payloads.
Content的提问来源于stack exchange,提问作者Justin Schultz

