【问题标题】:coldfusion get API token from salesforce - invalid grantColdfusion 从 Salesforce 获取 API 令牌 - 授权无效
【发布时间】:2020-01-30 01:06:23
【问题描述】:

我过得很糟糕......我正在尝试通过coldfusion从salesforce那里获得一个令牌,但我遇到了以下错误

{"error":"invalid_grant","error_description":"authentication failure"}

我试过 cfscript

local.http = new Http(url='https://test.salesforce.com/services/oauth2/token',method='post');

      local.http.addParam(type='header',name='content-type',   value='application/x-www-form-urlencoded');
      local.http.addParam(type='formField',name='grant_type',   value='password');
      local.http.addParam(type='formField',name='client_id',    value='client_id');
      local.http.addParam(type='formField',name='client_secret',  value='client_password_string');
      local.http.addParam(type='formField',name='username',   value='user@email.com');
      local.http.addParam(type='formField',name='password',   value='userspassword');
      local.http.addParam(type='formField',name='format',     value='json');

      local.httpSendResult = local.http.send();
      rc.httpResult = httpSendResult.getPrefix();

我试过 cfhttp 标签

<cfhttp url="https://test.salesforce.com/services/oauth2/token" method="POST">
         <cfhttpparam type="header" name="Content-Type" value="application/x-www-form-urlencoded" />
         <cfhttpparam type="formField" name="grant_type" value="password" />

         <cfhttpparam type="formField" name="client_id" value="client_id" />
         <cfhttpparam type="formField" name="client_secret" value="client_password_string" />
         <cfhttpparam type="formField" name="username" value="user@email.com" />
         <cfhttpparam type="formField" name="password" value="userspassword" />

        </cfhttp>       
        <cfset rc.result = cfhttp.fileContent />     

但是 cUrl 在我的本地机器上执行的完全相同的调用工作得非常好

    curl -d "grant_type=password" 
   -d "client_id=client_id" 
   -d "client_secret=client_secret_string" 
   -d "username=user@email.com.dev" 
   -d "password=userpassword" https://test.salesforce.com/services/oauth2/token

我确保我的 ip 范围被列入白名单,我的 ip 放宽设置为放宽,所有用户都可以自行授权,我尝试了不同的用户名和密码参数,我得到的只是关于无效授权的相同错误

非常感谢任何帮助

【问题讨论】:

  • cUrl 代码是用于发帖还是获取?
  • @DanBracuk 我认为它必须是一个帖子,我认为您不能将令牌请求作为获取

标签: coldfusion salesforce


【解决方案1】:

我无法发表评论,所以我必须回答:) 但这只是一个建议。当您使用 &lt;cfhttpparam type="formfield"&gt; 时,默认情况下 ColdFusion URL 会为您编码。 ColdFusion 将对字符 ~、.、- 和 _ 进行编码,但根据 RFC 3986 规范(请参阅 https://en.wikipedia.org/wiki/Percent-encoding),它实际上不应该这样做,因为它们是非保留字符。如果您的表单域包含这些字符(我怀疑它们包含这些字符,因为您的示例显示了一个电子邮件地址),那么这些字符编码不正确可能是导致身份验证失败的原因。

作为一个快速测试,您可以将encoded="false" 添加到您的&lt;cfhttpparam&gt; 标签,然后使用encodeForUrl() 或urlEncodedFormat()(取决于您的ColdFusion 版本)自己对其值进行url 编码,然后撤消不正确的编码:

 <cfhttpparam type="formField" encoded="false" name="username" value="#replacelist(urlEncodedFormat('user@email.com'), '%2D,%2E,%5F,%7E', '-,.,_,~')#">

【讨论】:

    【解决方案2】:

    下面是从我为访问 salesforce 创建的 CFC 中提取的一些 CFScript 代码。 (不会按原样运行,但逻辑是存在的——抱歉,复制完整的代码太多了)。希望它会有所帮助。

    我主要使用与您相同的方法,但您可能想窃取一些特定设置(字符集、内容类型、接受)。

    我伪造了 loginCredentials 结构中的值,但它们的格式大致相同(与您自己的比较)。

    这对我们在 Railo 上运行良好。也许还要检查这不是 SSL 问题 - 您是否需要将 SSL 证书添加到 Coldfusion 中以便它可以与 Salesforce 通信?

    variables.sfAuthDomain = "https://login.salesforce.com";
    
    variables.authServiceURL = variables.sfAuthDomain & "/services/oauth2/token";
    
    variables.accessToken = "xxxxx"    // The access token returned by SF, used on future logins
    
    variables.loginCredentials = {
        "grant_type": "password",
        "client_id": "3MVG9Fkjshdkfjvshd ckjfhjkch.blkjlkjlkjkljl.wkjhgkjhkjhds.mVk84TRzhm_pXxK6_786786",
        "client_secret": "3887687686868668727",
        "username": "huge.duck@monkey.com.icom.icomqa",
        "password": "Bungerloo!PPkjhj324ij45bQGyymmd"
    };
    
    
    /**
     * MAKE SERVICE CALL
     * Makes HTTP service call
     **/
    public Struct function makeServiceCall(String serviceUrl, String method="GET", Boolean sfAuth=true, Struct headers={}, Struct formFields) {
    
        var httpService = new http();    // create new http service
    
        var httpResponse = {};
    
        var fieldName = "";
    
        var bodyData = "";
    
        /* set attributes using implicit setters */
        httpService.setMethod(arguments.method);
        httpService.setCharset("utf-8");
        httpService.setUrl(Trim(arguments.serviceURL));
        httpService.setTimeOut(variables.timeoutValue);
    
        /* add httpparams using addParam() */        
        for(fieldName in arguments.headers) {
            httpService.addParam(type="header", name="#fieldName#", value="#arguments.headers[fieldName]#");            
        }
    
        if(arguments.sfAuth){
            httpService.addParam(type="header", name="Authorization", value="OAuth #variables.accessToken#");
        }
    
        if(StructKeyExists(arguments, "formFields")) {
            loop collection="#arguments.formFields#" item="fieldName" {
                bodyData = ListAppend(bodyData, "#fieldName#=#formFields[fieldName]#", "&");
            }
        }
    
        if(bodyData is not "") {
            httpService.addParam(type="body", name="post", encoded="no", value="#bodyData#");
        }
    
        /* make the http call to the URL using send() */
        httpResponse = httpService.send().getPrefix();
    
        //dump(httpResponse, false, "modern", "", 500, "httpResponse");
    
        return httpResponse;
    
    }
    
    httpResponse = makeServiceCall(
        serviceUrl = serviceURL,
        method = "POST", 
        sfAuth = false,
        headers = {
            "Content-Type": "application/x-www-form-urlencoded",
            "accept": "text/json"
        },
        formFields = loginCredentials    
    );
    

    【讨论】:

      【解决方案3】:

      最终将我的 Coldfusion 服务器更改为使用 TLS 1.2,因为 TLS 1.0 已被 Salesforce 弃用。希望我的回答和这篇文章中给出的有用答案对其他人有所帮助

      【讨论】:

        【解决方案4】:

        您的密码表单字段值仅包含密码,因此会显示这种错误:

        ({"error":"invalid_grant","error_description":"authentication failure"}).

        必须包含(密码和安全令牌)。

        &lt;cfhttpparam type="formField" name="password" value="#arguments.password##arguments.Security_token#"/&gt;

        【讨论】:

          猜你喜欢
          • 2016-10-13
          • 1970-01-01
          • 1970-01-01
          • 1970-01-01
          • 2018-10-01
          • 1970-01-01
          • 1970-01-01
          • 1970-01-01
          • 2020-07-12
          相关资源
          最近更新 更多