未经授权的 HTTP 请求 .NET

时间:2021-07-31 13:36:48

标签: c# .net http-headers authorization httprequest

我正在尝试使用承载授权发出 HTTP 请求。我有一个令牌,令牌有效。尝试以 3 种不同的方式执行此操作:应用程序,必须在 POSTMAN、控制台应用程序中实现该请求,并使用来自同一个 POSTMAN 调用的 POSTMAN (C# - RestSharp) 生成的代码:

应用 POST 方法:

public async Task<TResponse> Post<TRequest, TResponse>(string requestUri, TRequest data)
    {
        LogInit(requestUri, HttpMethod.Post, data);
        using (var request = new HttpRequestMessage(HttpMethod.Post, requestUri))
        {
            var token = await GetToken(_httpClient);
            request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", token.AccessToken);
            request.Content = new StringContent(JsonConvert.SerializeObject(data), Encoding.UTF8, "application/json");
            using (var response = await _httpClient.SendAsync(request))
            {
                if (!response.IsSuccessStatusCode)
                {
                    throw await HandleErrorResponse(response);
                }

                var responseObj = await response.Content.ReadAsJsonAsync<TResponse>();
                return responseObj;
            }
        }
    }

控制台 POST 方法:

static void Main(string[] args)
    {
        var client = new RestClient("http://***");
        client.Timeout = -1;
        var request = new RestRequest(Method.POST);
        request.AddHeader("Authorization", "Bearer xxx");
        request.AddHeader("Content-Type", "application/json");
        request.AddHeader("Cookie", "ARRAffinity=xxx");
        var body = @"{
            " + "\n" +
                        @"    ""amisPersonId"": ***,
            " + "\n" +
                        @"    ""name"": ""***"",
            " + "\n" +
                        @"    ""surname"": ""***"",
            " + "\n" +
                        @"    ""personalCode"": ""***"",
            " + "\n" +
                        @"    ""email"": ""***"",
            " + "\n" +
                        @"    ""phoneNumber"": ""***""
            " + "\n" +
        @"}";
        request.AddParameter("application/json", body, ParameterType.RequestBody);
        IRestResponse response = client.Execute(request);

        Console.WriteLine(response.Content);
    }

使用调试器跟踪的请求:

App request

Console app request

POSTMAN request

POSTMAN 获得 200/400 响应,应用和控制台应用获得 401(未经授权)。两个应用都是 .NET CORE 应用。

1 个答案:

答案 0 :(得分:0)

假设你有正确的 token.AccessToken ,尝试替换

 request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", token.AccessToken);

_httpClient.DefaultRequestHeaders.Authorization = new AuthenticationHeaderValue("Bearer", token.AccessToken);