OpenBankProject / OpenBankProject/OBP-API
Invalid signature problem
Nobody has claimed this yet.
- Dominant language
- Scala
- Stars
- 1.7k
- Forks
- 482
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 15
Description
I follow step by step this tutorial OAuth-1.0-Server to get the request token but I can't.
Assuming that my oauth_consumer_key=123 and my consumer_secret=456. My request would be the next:
POST /oauth/initiate HTTP/1.1
Host: api.openbankproject.com
Authorization: OAuth
oauth_callback=oob,
oauth_consumer_key="123",
oauth_signature_method="HMAC-SHA256",
oauth_timestamp="1522987628",
oauth_nonce="ErFKKs"
So, I encode the parameters in this way (Following the instructions):
-
First, the http method:
POST& -
Then, the base string URI encoded:
POST&https%3A%2F%2Fapi.openbankproject.com& -
Finally, I get the base string after normalizing the request parameters according to Section 3.4.1.3.2:
POST&https%3A%2F%2Fapi.openbankproject.com&oauth_callback%3Doob%26oauth_consumer_key%3D123%26oauth_nonce%3DErFKKs%26oauth_signature_method%3DHMAC-SHA256%26oauth_timestamp%3D1522987628 -
The secret is created by the concatenation of consumer_secret and oauth_consumer_key in this way:
456&123(consumer_secret&oauth_consumer_key) -
So, if I sign the base string with the secret
456&123using HMAC-SHA256 I get:
9a055becbf91403ec0ecc73f574862a7c9e77fcd27650ec5a530fbbfabe1f948 -
And after encoding to Base64 I get:
OWEwNTViZWNiZjkxNDAzZWMwZWNjNzNmNTc0ODYyYTdjOWU3N2ZjZDI3NjUwZWM1YTUzMGZiYmZhYmUxZjk0OA==
And it doesn't work !!! I cannot get my request token, my signature is wrong.
Am I doing something wrong ? Please, I need help
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the OAuth-1.0-Server tutorial and the POST /oauth/initiate request described in the issue, then compare the documented signature construction with the server's expected OAuth parameters. No repository file or test is named; done means identifying the cause of the rejected signature and documenting a confirmed correction or reproduction.
Written by the indexing model from the issue text.
Assessment
- Domain
- api, authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100