Auth 1.0 oauth_signature为magento API创建Android

时间:2018-03-27 06:37:26

标签: android rest authorization retrofit magento-1.9

我使用以下Autherization作为标题调用Magento API,

auth = "OAuth oauth_consumer_key=**********************,oauth_consumer_secret=****************,oauth_token=************,oauth_token_secret=**************,oauth_signature_method=HMAC-SHA1,oauth_timestamp=" + ConstantFunctions.GetTimeStamp() + ",oauth_nonce=" + ConstantFunctions.GetNonce() + ",oauth_signature=*******************) ;

我打电话给API, 获取错误oauth_problem=signature_invalid。所有其他参数验证成功,但签名中出错, 我尝试以下代码来生成签名

     public static String GETHMACSHA1(String value, String key)
            throws UnsupportedEncodingException, NoSuchAlgorithmException,
            InvalidKeyException {
        String type = "HmacSHA1";
        SecretKeySpec secret = new SecretKeySpec(key.getBytes(), type);
        Mac mac = Mac.getInstance(type);
        mac.init(secret);
        byte[] bytes = mac.doFinal(value.getBytes());
        return bytesToHex(bytes);
    }

    private final static char[] hexArray = "0123456789abcdef".toCharArray();

    private static String bytesToHex(byte[] bytes) {
        char[] hexChars = new char[bytes.length * 2];
        int v;
        for (int j = 0; j < bytes.length; j++) {
            v = bytes[j] & 0xFF;
            hexChars[j * 2] = hexArray[v >>> 4];
            hexChars[j * 2 + 1] = hexArray[v & 0x0F];
        }
        return new String(hexChars);
    }

我传递oauth_consumer_secretoauth_token_secret作为参数来获取签名。但它仍然会得到同样的错误。

如何在android中生成签名以及我需要传递哪个值才能获得相同的内容?

2 个答案:

答案 0 :(得分:4)

我们不需要将所有属性作为auth传递,改造本身处理这个,我们只需要传递CONSUMER_KEY,CONSUMER_SECRET,ACCESS_TOKEN和TOKEN_SECRET。

关注this

ApiUtils类就像,

科特林

class ApiUtils {
companion object {
    fun getAPIService(): APIService? {
        val consumer = OkHttpOAuthConsumer(BuildConfig.CONSUMER_KEY, BuildConfig.CONSUMER_SECRET)
        consumer.setTokenWithSecret(BuildConfig.ACCESS_TOKEN, BuildConfig.TOKEN_SECRET)
        return RetrofitClient.getClient(BuildConfig.BASE_URL, consumer)?.create(APIService::class.java)
    }
}

}

Android Java

public class ApiUtils {

    private ApiUtils() {
    }

    private static final String BASE_URL = BuildConfig.BASE_URL;

    public static APIService getAPIService() {

        OkHttpOAuthConsumer consumer = new OkHttpOAuthConsumer(BuildConfig.CONSUMER_KEY, BuildConfig.CONSUMER_SECRET);
        consumer.setTokenWithSecret(BuildConfig.ACCESS_TOKEN, BuildConfig.TOKEN_SECRET);

        OkHttpClient client = new OkHttpClient.Builder()
                .addInterceptor(new SigningInterceptor(consumer))
                .build();
        return RetrofitClient.getClient(BASE_URL, client).create(APIService.class);
    }
}

RetrofitClient Class

科特林

    class RetrofitClient {
    companion object {
        private var retrofit: Retrofit? = null
        private val gSON = GsonBuilder()
            .setLenient()
            .create()

        fun getClient(baseUrl: String, consumer: OkHttpOAuthConsumer): Retrofit? {
            val logging = HttpLoggingInterceptor()
            if (BuildConfig.DEBUG) {
                logging.level = HttpLoggingInterceptor.Level.BODY
            } else {
                logging.level = HttpLoggingInterceptor.Level.NONE
            }

            val httpClient = OkHttpClient.Builder()
            httpClient.connectTimeout(60000, TimeUnit.SECONDS)
            httpClient.writeTimeout(120000, TimeUnit.SECONDS)
            httpClient.readTimeout(120000, TimeUnit.SECONDS)
            httpClient.retryOnConnectionFailure(true)
            httpClient.addInterceptor(SigningInterceptor(consumer))
            httpClient.addInterceptor { chain ->
                val request = chain.request()
                val requestBuilder = request.newBuilder()
                    .header(HEADER_CONTENT_TYPE_KEY, PreferenceHandler.getContentType())
                    .header(HEADER_ACCEPT_KEY, PreferenceHandler.getAcceptType())
                    .header(HEADER_CACHE_CONTROL_KEY, PreferenceHandler.getCacheControl())
                val modifiedRequest = requestBuilder.build()
                chain.proceed(modifiedRequest)
            }

            httpClient.addNetworkInterceptor(logging)

            if (retrofit == null) {
                retrofit = Retrofit.Builder()
                    .baseUrl(baseUrl)
                    .addConverterFactory(GsonConverterFactory.create(gSON))
                    .client(httpClient.build())
                    .build()
            }
            return retrofit
        }

    }
}

Android java

public class RetrofitClient {

    private static Retrofit retrofit = null;

    public static Retrofit getClient(String baseUrl,OkHttpClient client) {
        if (retrofit == null) {
            retrofit = new Retrofit.Builder()
                    .baseUrl(baseUrl)
                    .client(client)
                    .addConverterFactory(GsonConverterFactory.create())
                    .build();
        }
        return retrofit;
    }
}

答案 1 :(得分:1)

对于Oauth,我不认为你应该通过CS和TS。您需要连接一组URL编码的属性和参数来构造签名基本字符串。请参考 - devdocs.magento.com/guides/v2.0/get-started/authentication /

  

所以换句话说,SHA1中的一个参数将是一个编码的URL   它应该是以HTTP方法开头的特定格式。

enter image description here

url在编码之前应包含上述参数。

我在Woocommerce API for android中进行了类似的Oauth身份验证,请参阅此gist网址以获取更多信息。

https://gist.github.com/Muneefm/f4c08b2aa3accd57fa890156f74e619a

在此检查名为getLoginUrl()的方法。其中我连接了网址。