You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Android中OAuth2密码授权POST请求400错误,如何日志完整请求

Debugging Your 400 Bad Request: Logging the Full POST Request

Got it, let's fix your logging so you can see exactly what's being sent to the API and debug that 400 error. The main issue right now is that your postData.toString() call isn't showing the actual request body—it's just returning the byte array's internal hash representation, not the parameter string you built.

Here's how to properly log every part of your POST request:

Key Fixes & Improvements

  • Log the actual request body: Use your existing urlParameters string directly (no need to convert it to a byte array first for logging).
  • Log the full request URL: Match the format you wanted to see, like API Call Made = "https://api.allthingstalk.io/login".
  • Log critical request headers: OAuth2's password grant relies on specific headers (like grant_type)—logging these will help you spot typos or missing values.
  • Avoid logging sensitive data: Never log passwords in production—I've added a redaction note for that below.

Modified Code with Proper Logging

@RequiresApi(api = Build.VERSION_CODES.KITKAT)
public static Token getAccessToken () {
    Token accessToken = null;
    String urlParameters = "param1=a&param2=b&param3=c";
    byte[] postData = urlParameters.getBytes(StandardCharsets.UTF_8);
    
    try {
        URL url = new URL("https://api.allthingstalk.io/login");
        HttpURLConnection client = (HttpURLConnection) url.openConnection();
        
        // Set request properties
        client.setRequestMethod("POST");
        client.setRequestProperty("grant_type", "password");
        client.setRequestProperty("username", username);
        client.setRequestProperty("password", password);
        client.setRequestProperty("client_id", "com.example.gebruiker.internetofthingsattplatform");
        // Fix typo here: "Content-Type:" has an extra colon, which might be causing your 400!
        client.setRequestProperty("Content-Type", "application/x-www-form-urlencoded");
        client.setUseCaches(false);
        client.setDoOutput(true);
        
        // Log the full request details
        Log.d(TAG, "API Call Made = \"" + url.toString() + "\"");
        Log.d(TAG, "Request Method: POST");
        Log.d(TAG, "Request Headers:");
        Log.d(TAG, "  grant_type: password");
        Log.d(TAG, "  username: " + username);
        // WARNING: Remove this line in production! Never log passwords.
        Log.d(TAG, "  password: [REDACTED]"); // Replace with actual password only for local debugging
        Log.d(TAG, "  client_id: com.example.gebruiker.internetofthingsattplatform");
        Log.d(TAG, "  Content-Type: application/x-www-form-urlencoded");
        Log.d(TAG, "Request Body: " + urlParameters);
        
        // Send the request
        OutputStream outputStream = new BufferedOutputStream(client.getOutputStream());
        outputStream.write(postData);
        outputStream.flush();
        outputStream.close();
        
        // Log response status
        int status = client.getResponseCode();
        Log.d(TAG, "Response Status Code: " + status);
        
        if (client != null) {
            client.disconnect();
        }
    } catch(MalformedURLException error) {
        Log.e(TAG, "Invalid URL", error);
    } catch(SocketTimeoutException error) {
        Log.e(TAG, "Request timed out", error);
    } catch (IOException error) {
        Log.e(TAG, "IO Error", error);
    }
    return accessToken;
}

Bonus: Critical Typo Fix

I noticed you had a typo in your Content-Type header: client.setRequestProperty("Content-Type:", "application/x-www-form-urlencoded"); includes an extra colon at the end of the header name. That's almost certainly contributing to your 400 Bad Request error—HTTP headers can't have colons in their names. I fixed that in the code above.

Important Note

When you're done debugging, make sure to remove any logs that include sensitive data like passwords. Exposing credentials in logs is a major security risk.

内容的提问来源于stack exchange,提问作者Niels Vanwingh

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:40:59