授权成功但OAuth令牌交换失败——ServiceM8应用ID 133481求助
授权成功但OAuth令牌交换失败——ServiceM8应用ID 133481
我在ServiceM8应用的OAuth集成中遇到问题,请求协助解决令牌交换流程相关问题。
应用详情:
- 应用ID:
133481 - 应用类型: Web Service Hosted Add-on
- 重定向URI:
https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback
问题概述
OAuth授权流程已成功完成,但令牌交换回调从未被触发,导致我的应用无法获取访问令牌。
正常工作项:
- OAuth授权请求可正确重定向至ServiceM8
- 用户可成功接受权限
- ServiceM8会返回成功提示并重定向
异常项:
- 回调端点从未收到授权码
- 授权成功后无回调处理日志
- API请求持续收到401“无效的用户名或密码”错误
技术实现
OAuth授权请求:
const authUrl = `https://go.servicem8.com/oauth/authorize?` + `client_id=133481&` + `redirect_uri=${encodeURIComponent('https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback')}&` + `response_type=code&` + `scope=${encodeURIComponent('read_staff staff_activity read_jobs read_job_categories read_schedule read_customers read_job_queues read_tasks')}&` + `state=${randomState}`;
回调实现:
app.get("/auth/servicem8/callback", async (req, res) => { console.log('ServiceM8 OAuth callback received:', req.query); const { code, error } = req.query; if (error) { return res.redirect('/?auth=servicem8_error'); } if (!code) { return res.status(400).json({ error: "缺少授权码" }); } try { const params = new URLSearchParams(); params.append('grant_type', 'authorization_code'); params.append('client_id', '133481'); params.append('client_secret', '[APP_SECRET]'); params.append('code', code); params.append('redirect_uri', 'https://service-m-8-performance-martinsudell.replit.app/auth/servicem8/callback'); const tokenResponse = await axios.post('https://go.servicem8.com/oauth/access_token', params, { headers: { 'Content-Type': 'application/x-www-form-urlencoded', 'Accept': 'application/json' } }); // 存储令牌并跳转到成功页面 } catch (error) { console.error('令牌交换失败:', error); } });
manifest.json
{ "name": "Team Performance Dashboard", "version": "4.0", "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png", "supportURL": "https://service-m-8-performance-martinsudell.replit.app", "supportEmail": "support@example.com", "oauth": { "scope": "read_staff staff_activity read_jobs read_job_categories read_schedule read_customers read_job_queues read_tasks" }, "actions": [{ "name": "Performance Dashboard", "type": "online", "entity": "company", "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png", "event": "dashboard_open", "location": "modal" }], "menuItems": [{ "name": "Team Performance", "type": "addon", "iconURL": "https://sudell.co.uk/wp-content/uploads/2019/04/Logo@3x.png", "event": "dashboard_open" }] }
当前行为
尽管授权成功,但回调端点从未收到任何请求。控制台日志显示OAuth请求已发起,但无对应回调处理日志。
API请求尝试
当前API请求返回:
- 状态码:401 Unauthorized
- 响应内容:"无效的用户名或密码"
- 无OAuth令牌时使用Basic Auth降级方案
协助请求
恳请协助验证应用ID 133481的OAuth配置,并确认:
- 正确的回调URL格式及令牌交换流程
- Web Service Hosted Add-on是否有特定要求
- OAuth流程是否需额外配置步骤
我已提供完整技术实现,如需更多调试信息可随时提供。
感谢支持!
内容的提问来源于stack exchange,提问作者Martin Sudell
相关产品推荐
相关产品推荐

