lepture / authlib OAuth2客户端和Session有什么区别?

时间:2018-10-19 05:53:00

标签: rest api oauth-2.0 authlib

我正在实现OAuth2客户端应用程序以连接到this服务器。到目前为止,我已经设法使用Authlib的OAuth2Session实例获取资源/ api / me。我已经用OAuthClient进行了尝试,但是它没有用,尽管Client类具有类似put, post, get, delete的方法,所以它适合访问我想的资源。 :/

那有什么区别,为什么我可以使用Session的实例访问/api/me而不能使用Client的实例访问?

这是我的代码:

    def api_me_get2(token):
    print("========================================")
    print("Sending 2nd GET request to get protected data of me")

    oauth2_client = OAuthClient(
        client_id='ySFTzBKLo0XTaK2tQL9ls4Fc',
        client_secret='vq8vMZplY4J00FrxKx4ynV2mhmL2zzjMzP1U2bXZPhQRcmJl',
        api_base_url=_url(""),
        access_token_url=_url(f"/oauth/token"),
        authorize_url=_url("/oauth/authorize"),
        client_kwargs={"scope":"profile"},
#        client_kwargs={'scope': 'user:email'},
    )

    new_token = oauth2_client.fetch_access_token();
    print(f"New token \"{new_token}\"")
    # FORM data
    '''
    payload = {
        "token":f"{token}"
    }
    print(f"PAYLOAD=\"{payload}\"")
    r = requests.get(_url(f"/api/me"), data=payload, params=payload)
    print(f"RESPONSE {r.status_code}")
    print(f"r.url={r.url}")
    print(f"r.text={r.text}")
    if r.status_code == 200:
        json = r.json()
        print(f"JSON=\"{json}\"")
    '''
    print("========================================")

def api_me_get3(token):
    print("========================================")
    print("Sending 3rd GET request to get protected data of me")

    oauth2_session = OAuth2Session(
        client_id="ySFTzBKLo0XTaK2tQL9ls4Fc",
        client_secret="vq8vMZplY4J00FrxKx4ynV2mhmL2zzjMzP1U2bXZPhQRcmJl",
        token_endpoint_auth_method=None,
        refresh_token_url=_url("/oauth/revoke"),
        refresh_token_params=None,
        scope="profile",
        redirect_uri=None,
        token=token,
        token_placement='header',
        state=None,
        token_updater=None
    )

    r = oauth2_session.request("GET", _url("/api/me"), withhold_token=False, auth=None)

    print(f"Request: \"{r}\"")

    print(f"RESPONSE {r.status_code}")
    print(f"r.url={r.url}")
    print(f"r.text={r.text}")
    if r.status_code == 200:
        json = r.json()
        print(f"JSON=\"{json}\"")

#    new_token = oauth2_client.fetch_access_token();
#    print(f"New token \"{new_token}\"")
    # FORM data
    '''
    payload = {
        "token":f"{token}"
    }
    print(f"PAYLOAD=\"{payload}\"")
    r = requests.get(_url(f"/api/me"), data=payload, params=payload)
    print(f"RESPONSE {r.status_code}")
    print(f"r.url={r.url}")
    print(f"r.text={r.text}")
    if r.status_code == 200:
        json = r.json()
        print(f"JSON=\"{json}\"")
    '''
    print("========================================")

1 个答案:

答案 0 :(得分:1)