Coinbase Api Java POST请求“无效签名”

时间:2018-08-04 22:29:09

标签: java post bitcoin signature coinbase-api

我正在尝试向硬币库沙箱端点发送POST请求。在签署请求时,我总是收到“无效签名”响应。似乎coinbase要求JSON消息必须进行base 64编码并作为签名的一部分发送。我对POST请求还很陌生,以前从未签名过消息。有人可以让我知道我在做什么错。我已经在这个问题上停留了一个星期,因此非常感谢您的投入。

我的代码的相关部分在下面

public void postOrder() throws InvalidKeyException, NoSuchAlgorithmException, CloneNotSupportedException, ClientProtocolException, IOException {

    String message = "{ \n"+
               " \"size\":\"1.00\", \n"+
               " \"price\":\"0.80\", \n"+
               " \"side\":\"buy\", \n"+
               " \"product_id\":\"BTC-USD\" \n"+
               "}"; 

    JSONObject json = new JSONObject(message);
    message = json.toString();
    try
    {
            String timestamp= Instant.now().getEpochSecond()+"";
            String accessSign = getAccess(timestamp,"POST","/orders",message);
            String apiKey = properties.getProperty("key");
            String passphrase = properties.getProperty("passphrase");

            URL url = new URL("https://api-public.sandbox.pro.coinbase.com/orders");
            HttpURLConnection connection = (HttpURLConnection)url.openConnection();
            connection.setDoOutput(true); 
            connection.setRequestProperty("accept", "application/json");
            connection.setRequestProperty("content-type", "application/json; charset=UTF-8");
            connection.setRequestProperty("CB-ACCESS-KEY", apiKey);
            connection.setRequestProperty("CB-ACCESS-SIGN", accessSign);
            connection.setRequestProperty("CB-ACCESS-TIMESTAMP", timestamp);
            connection.setRequestProperty("CB-ACCESS-PASSPHRASE", passphrase);
            connection.setRequestProperty("User-Agent", "Java Client"); 

          try { 
            connection.getOutputStream().write(message.getBytes("UTF-8"));
            OutputStream output = connection.getOutputStream(); 
            output.write(param.getBytes("UTF-8"));
          } catch (Exception e) {
              System.out.println(e.getMessage());
          }

          String status = connection.getResponseMessage();
            System.out.println("STATUS: "+status);  

     }catch(Exception e) {
        System.out.println(e.getMessage());
     }
     return;
}


 private String getAccess(String timestamp, String method, String path, String param) throws NoSuchAlgorithmException, InvalidKeyException, CloneNotSupportedException, IllegalStateException, UnsupportedEncodingException {

        String secretKeyString = properties.getProperty("secret");

        String prehash = timestamp+method+path+param;
        byte[] secretKeyDecoded = Base64.getDecoder().decode(secretKeyString);
        SecretKey secretKey = new SecretKeySpec(secretKeyDecoded, "HmacSHA256");
        Mac hmacSha256 = Mac.getInstance("HmacSHA256");
        hmacSha256.init(secretKey);

        return Base64.getEncoder().encodeToString(hmacSha256.doFinal(prehash.getBytes()));
 }

1 个答案:

答案 0 :(得分:0)

就我而言,我使用了gdax-java的示例。我通过从时间戳中删除十进制值解决了这个问题,这意味着我只使用了时间戳值的整数部分。