【问题标题】:Google Analytics OAuth2: How to solve error: "redirect_uri_mismatch"?Google Analytics OAuth2:如何解决错误:“redirect_uri_mismatch”?
【发布时间】:2016-05-18 18:34:42
【问题描述】:

我正在尝试让这个示例工作:https://developers.google.com/analytics/devguides/config/mgmt/v3/quickstart/web-php#enable

我得到的错误是“错误:redirect_uri_mismatch”。

为了安装google api资源,我使用了composer这个命令:

php composer.phar require google/apiclient:^2.0.0@RC

这在我的根站点文件夹中安装了“供应商”文件夹。我的 index.php 和 oauth2callback.php 文件位于“public_html”文件夹中。

这是我在访问我的网站时出错的屏幕截图:

奇怪的是,如果我导航到错误消息“访问......以更新授权..”中包含的上述链接,我会收到以下错误消息:“OAuth 客户端不存在"

如果我点击我唯一可用的客户端 ID,我可以导航查看 URI,我也会在下面截屏:

如您所见,在授权的 Javascript 来源下,我列出了 http://localhost,在授权的重定向 URI 下,我的实时站点后跟“oauthc2callback.php”文件扩展名。

我不明白如何摆脱我遇到的错误。我尝试替换 URI 并放入不同的 JavaScript 来源。

此外,由于某种原因,在最后一张屏幕截图中,它说我无权编辑此 OAuth 客户端,但我可以进行编辑。

我的 index.php 代码:

<?php
// Load the Google API PHP Client Library.
require_once '../vendor/autoload.php';

// Start a session to persist credentials.
session_start();

// Create the client object and set the authorization configuration
// from the client_secretes.json you downloaded from the developer console.
$client = new Google_Client();
$client->setAuthConfigFile('../config/client_secrets.json');
$client->addScope('https://www.googleapis.com/auth/analytics.readonly');

// If the user has already authorized this app then get an access token
// else redirect to ask the user to authorize access to Google Analytics.
if (isset($_SESSION['access_token']) && $_SESSION['access_token']) {
    // Set the access token on the client.
    $client->setAccessToken($_SESSION['access_token']);

    // Create an authorized analytics service object.
    $analytics = new Google_Service_Analytics($client);

    // Get the first view (profile) id for the authorized user.
    $profile = getFirstProfileId($analytics);

    // Get the results from the Core Reporting API and print the results.
    $results = getResults($analytics, $profile);
    printResults($results);
} else {
    $redirect_uri = 'http://' . $_SERVER['HTTP_HOST'] . '/oauth2callback.php';
    header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL));
}


function getFirstprofileId(&$analytics) {
    // Get the user's first view (profile) ID.

    // Get the list of accounts for the authorized user.
    $accounts = $analytics->management_accounts->listManagementAccounts();

    if (count($accounts->getItems()) > 0) {
        $items = $accounts->getItems();
        $firstAccountId = $items[0]->getId();

        // Get the list of properties for the authorized user.
        $properties = $analytics->management_webproperties
        ->listManagementWebproperties($firstAccountId);

        if (count($properties->getItems()) > 0) {
            $items = $properties->getItems();
            $firstPropertyId = $items[0]->getId();

            // Get the list of views (profiles) for the authorized user.
            $profiles = $analytics->management_profiles
            ->listManagementProfiles($firstAccountId, $firstPropertyId);

            if (count($profiles->getItems()) > 0) {
                $items = $profiles->getItems();

                // Return the first view (profile) ID.
                return $items[0]->getId();

            } else {
                throw new Exception('No views (profiles) found for this user.');
            }
        } else {
            throw new Exception('No properties found for this user.');
        }
    } else {
        throw new Exception('No accounts found for this user.');
    }
}

function getResults(&$analytics, $profileId) {
    // Calls the Core Reporting API and queries for the number of sessions
    // for the last seven days.
    return $analytics->data_ga->get(
    'ga:' . $profileId,
    '7daysAgo',
    'today',
    'ga:sessions');
}

function printResults(&$results) {
    // Parses the response from the Core Reporting API and prints
    // the profile name and total sessions.
    if (count($results->getRows()) > 0) {

        // Get the profile name.
        $profileName = $results->getProfileInfo()->getProfileName();

        // Get the entry for the first entry in the first row.
        $rows = $results->getRows();
        $sessions = $rows[0][0];

        // Print the results.
        print "<p>First view (profile) found: $profileName</p>";
        print "<p>Total sessions: $sessions</p>";
    } else {
        print "<p>No results found.</p>";
    }
}

“oauth2callback.php”的代码:

<?php
require_once '../vendor/autoload.php';

// Start a session to persist credentials.
session_start();

// Create the client object and set the authorization configuration
// from the client_secrets.json you downloaded from the Developers Console.
$client = new Google_Client();
$client->setAuthConfigFile('../config/client_secrets.json');
$client->setRedirectUri('http://' . $_SERVER['HTTP_HOST'] . '/oauth2callback.php');
$client->addScope('https://www.googleapis.com/auth/analytics.readonly');

// Handle authorization flow from the server.
if (! isset($_GET['code'])) {
    $auth_url = $client->createAuthUrl();
    header('Location: ' . filter_var($auth_url, FILTER_SANITIZE_URL));
} else {
    $client->authenticate($_GET['code']);
    $_SESSION['access_token'] = $client->getAccessToken();
    $redirect_uri = 'http://' . $_SERVER['HTTP_HOST'] . '/';
    header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL));
}

所有这些代码都取自第一个网站示例,除了一些小的添加以使其与我的系统匹配。

有人知道我怎样才能摆脱这个错误吗?我做错了什么?

【问题讨论】:

    标签: redirect oauth google-analytics oauth-2.0 uri


    【解决方案1】:

    请记住,就 Google 而言,“您的”服务器是敌对的,直到您将其命名为“友好”,您必须明确将 OAuth 调用的所有可能来源列入白名单。

    Google 是一个俱乐部保镖,一个又大又丑、不可移动的保镖,有一个客人名单对您的应用程序说:“如果您的确切姓名或身份证在名单上,我只会处理您的请求”

    您是否尝试过不仅包括localhost,还包括所有其他可能的来源?

    您必须列出 URL“root”的所有可能变体,包括显式 IP。

    http://www.example.com
    http://example.com
    https://example.com
    https://www.example.com
    http://222.111.0.111
    ...
    

    别忘了包含

    https://accounts.google.com:443

    【讨论】:

    • 原点应该是什么?例如,如果我的项目 URL 是 www.ffy.thisismydomain.com,原点是否仍应为 localhost
    • 您说不要忘记包含该 account.google 网址,您的意思是作为 URI 之一吗?
    • 等待所有这些不同的 URL 再现,我应该将其作为来源还是重定向?
    • Authorized Javascript OriginsRestrictions 下。一次输入一个原始 URL,您将得到一长串可能的服务器 URL。如果其中一个与请求的 ORIGIN 匹配,Google 会回答。如果没有,您将收到重定向 uri 错误。
    • 感谢您的所有帮助。
    【解决方案2】:

    请求中的重定向 Uri 必须与您存储的一个 Uri 完全相同。

    我在您的请求中遗漏的存储的末尾看到一个 /。

    【讨论】:

    • 您是对的,您列出的各种 URL 中至少有一个必须与发起请求的站点的 URL 完全匹配。
    • 那么作为URI,我应该把最后的“/”去掉吗?
    • 就是这样。在你的情况下,这个尾随 / 似乎没用。
    【解决方案3】:

    只需从错误屏幕复制发生错误的请求 URI 并将其粘贴到 OAuth 凭据“授权重定向 URI”

    现在运行应用程序。 这对我有用。希望我回答了您的问题。

    【讨论】:

      猜你喜欢
      • 2021-06-22
      • 2018-03-22
      • 2020-06-04
      • 2014-12-04
      • 1970-01-01
      • 2016-09-15
      • 1970-01-01
      • 1970-01-01
      • 2019-05-13
      相关资源
      最近更新 更多