You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

授权成功但OAuth令牌交换失败——ServiceM8应用ID 133481求助

授权成功但OAuth令牌交换失败——ServiceM8应用ID 133481

我在ServiceM8应用的OAuth集成中遇到问题,请求协助解决令牌交换流程相关问题。


应用详情:

  • 应用ID: 133481
  • 应用类型: Web Service Hosted Add-on
  • 重定向URI: https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback

问题概述

OAuth授权流程已成功完成,但令牌交换回调从未被触发,导致我的应用无法获取访问令牌。


正常工作项:

  • OAuth授权请求可正确重定向至ServiceM8
  • 用户可成功接受权限
  • ServiceM8会返回成功提示并重定向

异常项:

  • 回调端点从未收到授权码
  • 授权成功后无回调处理日志
  • API请求持续收到401“无效的用户名或密码”错误

技术实现

OAuth授权请求:

const authUrl = `https://go.servicem8.com/oauth/authorize?` +
  `client_id=133481&` +
  `redirect_uri=${encodeURIComponent('https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback')}&` +
  `response_type=code&` +
  `scope=${encodeURIComponent('read_staff staff_activity read_jobs read_job_categories read_schedule read_customers read_job_queues read_tasks')}&` +
  `state=${randomState}`;

回调实现:

app.get("/auth/servicem8/callback", async (req, res) => {
  console.log('ServiceM8 OAuth callback received:', req.query);

  const { code, error } = req.query;

  if (error) {
    return res.redirect('/?auth=servicem8_error');
  }

  if (!code) {
    return res.status(400).json({ error: "缺少授权码" });
  }

  try {
    const params = new URLSearchParams();
    params.append('grant_type', 'authorization_code');
    params.append('client_id', '133481');
    params.append('client_secret', '[APP_SECRET]');
    params.append('code', code);
    params.append('redirect_uri', 'https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback');

    const tokenResponse = await axios.post('https://go.servicem8.com/oauth/access_token', params, {
      headers: {
        'Content-Type': 'application/x-www-form-urlencoded',
        'Accept': 'application/json'
      }
    });

    // 存储令牌并跳转到成功页面
  } catch (error) {
    console.error('令牌交换失败:', error);
  }
});

manifest.json

{
  "name": "Team Performance Dashboard",
  "version": "4.0",
  "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png",
  "supportURL": "https://service-m-8-performance-martinsudell.replit.app",
  "supportEmail": "support@example.com",
  "oauth": {
    "scope": "read_staff staff_activity read_jobs read_job_categories read_schedule read_customers read_job_queues read_tasks"
  },
  "actions": [{
    "name": "Performance Dashboard",
    "type": "online",
    "entity": "company",
    "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png",
    "event": "dashboard_open",
    "location": "modal"
  }],
  "menuItems": [{
    "name": "Team Performance",
    "type": "addon",
    "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png",
    "event": "dashboard_open"
  }]
}

当前行为

尽管授权成功,但回调端点从未收到任何请求。控制台日志显示OAuth请求已发起,但无对应回调处理日志。


API请求尝试

当前API请求返回:

  • 状态码:401 Unauthorized
  • 响应内容:"无效的用户名或密码"
  • 无OAuth令牌时使用Basic Auth降级方案

协助请求

恳请协助验证应用ID 133481的OAuth配置,并确认:

  • 正确的回调URL格式及令牌交换流程
  • Web Service Hosted Add-on是否有特定要求
  • OAuth流程是否需额外配置步骤

我已提供完整技术实现,如需更多调试信息可随时提供。

感谢支持!

内容的提问来源于stack exchange,提问作者Martin Sudell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 00:24:54