谷歌验证:OAuth2不断返回'invalid_grant'

时间:2020-12-12 15:47:29

I started to configure google calendar on my new application. I almost made an exact copy of the authentication code displayed at google developers ( https://developers.google.com/google-apps/calendar/instantiate ), but i keep getting the following error:

我开始在我的新应用程序上配置谷歌日历。我几乎完成了Google开发人员显示的身份验证代码的完整副本(https://developers.google.com/google-apps/calendar/instantiate),但我不断收到以下错误:

Error fetching OAuth2 access token, message: 'invalid_grant'

获取OAuth2访问令牌时出错,消息:'invalid_grant'

I'm currently using Fork-CMS ( http://www.fork-cms.com ), a young lightweigth CMS. I correctly configured the config.php file of the google-api-php-client. (client-id, client-secret, redirect-uri, development key,...) and the redirect uri is correctly set on the google api's console. My code looks as follows:

我目前正在使用Fork-CMS(http://www.fork-cms.com),一个年轻的lightweigth CMS。我正确配置了google-api-php-client的config.php文件。 (客户端ID,客户端密码,redirect-uri,开发密钥,...)和重定向uri在google api的控制台上正确设置。我的代码如下:

<?php

/**
* This is a widget with a calendar implementation.
*
* @package       frontend
* @subpackage    events
*
* @author        Michiel Vlaminck <michielvlaminck@gmail.com>
*/
class FrontendEventsWidgetCalendar extends FrontendBaseWidget
{

    private $events = array();
    private $authUrl = array();

    /**
    * Execute the extra
    *
    * @return    void
    */
    public function execute()
    {      
        // call parent
        parent::execute();

        // load template
        $this->loadTemplate();

        // get data
        $this->getData();

        // parse
        $this->parse();
    }


    /**
    * Get the data from Google Calendar
    * This method is only executed if the template isn't cached
    *
    * @return    void
    */
    private function getData()
    {
        require_once PATH_LIBRARY . '/external/google-api-php-client/src/apiClient.php';
        require_once PATH_LIBRARY . '/external/google-api-php-client/src/contrib/apiCalendarService.php';

        $client = new apiClient();

        $service = new apiCalendarService($client);

        if (isset($_SESSION['oauth_access_token'])) {
            $client->setAccessToken($_SESSION['oauth_access_token']);
        } else {
            $token = $client->authenticate();
            $_SESSION['oauth_access_token'] = $token;
        }

        if ($client->getAccessToken()) {

            $calId = FrontendEventsModel::getCalendarId((int) $this->data['id']);
            $calId = $calId[0]['calendar_id'];

            $events = $service->events->listEvents($calId);
            $this->events = $events['items'];

            $_SESSION['oauth_access_token'] = $client->getAccessToken();

        } else {
            $this->authUrl = $client->createAuthUrl();
        }
    }


    /**
    * Parse
    *
    * @return    void
    */
    private function parse()
    {
        $this->tpl->assign('events', $this->events);
        $this->tpl->assign('authUrl', $this->authUrl);
    }
}

?>

When I open this widget-page for the first time, I get directed to google to authenticate the application. When I agree, I get redirected to my application and that's the point where I'm getting:

当我第一次打开这个小部件页面时,我会被引导到谷歌来验证应用程序。当我同意时,我会被重定向到我的应用程序,这就是我得到的地方:

apiAuthException » Main

Message Error fetching OAuth2 access token, message: 'invalid_grant'
File    C:\wamp\www\Officevibes\library/external\google-api-php-client\src\auth\apiOAuth2.php
Line    105
Date    Thu, 05 Apr 2012 08:34:47 +0000
URL http://localhost/calendar?code=4/YPUpFklKvhEeTcMm4moRth3x49oe
Referring URL   (Unknown)
Request Method  GET
User-agent  Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/535.19 (KHTML, like Gecko) Chrome/18.0.1025.142 Safari/535.19

5 个解决方案

#1


22  

You should reuse the access token you get after the first successful authentication. You will get an invalid_grant error if your previous token has not expired yet. Cache it somewhere so you can reuse it.

您应该重用第一次成功验证后获得的访问令牌。如果您之前的令牌尚未过期,您将收到invalid_grant错误。将其缓存在某处,以便您可以重复使用它。

#2


9  

I was having a similar problem caused by the time on my server being incorrect. Make sure your system clock is synchronised.

我的服务器上的时间不正确导致了类似的问题。确保系统时钟同步。

#3


8  

Go to your Google API Console ( https://code.google.com/apis/console/ ) and revoke your Client Secret under Client ID for installed applications.

转到您的Google API控制台(https://code.google.com/apis/console/),并在客户端ID下撤消已安装应用程序的客户端密钥。

Be sure to also update your code with the new Client Secret

请务必使用新的客户端密钥更新您的代码

#4


3  

  1. Go to security.google.com
  2. 转到security.google.com
  3. Revoke access
  4. 撤消访问权限
  5. visit the authentication url again
  6. 再次访问身份验证网址
  7. you will now get a new refreshtoken
  8. 你现在将得到一个新的refreshtoken

#5


1  

You'll also receive this error if you mistakenly try to authenticate your ID Token, rather than your Access Token.

如果您错误地尝试验证您的ID令牌而不是您的访问令牌,您也会收到此错误。

So don't be like me - Make sure you pass the correct token into your code!

所以不要像我一样 - 确保将正确的令牌传递给您的代码!

#1


22  

You should reuse the access token you get after the first successful authentication. You will get an invalid_grant error if your previous token has not expired yet. Cache it somewhere so you can reuse it.

您应该重用第一次成功验证后获得的访问令牌。如果您之前的令牌尚未过期,您将收到invalid_grant错误。将其缓存在某处,以便您可以重复使用它。

#2


9  

I was having a similar problem caused by the time on my server being incorrect. Make sure your system clock is synchronised.

我的服务器上的时间不正确导致了类似的问题。确保系统时钟同步。

#3


8  

Go to your Google API Console ( https://code.google.com/apis/console/ ) and revoke your Client Secret under Client ID for installed applications.

转到您的Google API控制台(https://code.google.com/apis/console/),并在客户端ID下撤消已安装应用程序的客户端密钥。

Be sure to also update your code with the new Client Secret

请务必使用新的客户端密钥更新您的代码

#4


3  

  1. Go to security.google.com
  2. 转到security.google.com
  3. Revoke access
  4. 撤消访问权限
  5. visit the authentication url again
  6. 再次访问身份验证网址
  7. you will now get a new refreshtoken
  8. 你现在将得到一个新的refreshtoken

#5


1  

You'll also receive this error if you mistakenly try to authenticate your ID Token, rather than your Access Token.

如果您错误地尝试验证您的ID令牌而不是您的访问令牌,您也会收到此错误。

So don't be like me - Make sure you pass the correct token into your code!

所以不要像我一样 - 确保将正确的令牌传递给您的代码!