OpenBankProject / OpenBankProject/OBP-API

Invalid signature problem

Open
#1,002 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Scala
Stars
1.7k
Forks
482
Avg merge
1d 12h
Merged PRs (30d)
15

Description

I follow step by step this tutorial OAuth-1.0-Server to get the request token but I can't.

Assuming that my oauth_consumer_key=123 and my consumer_secret=456. My request would be the next:

POST /oauth/initiate HTTP/1.1
Host: api.openbankproject.com
Authorization: OAuth
oauth_callback=oob,
oauth_consumer_key="123",
oauth_signature_method="HMAC-SHA256",
oauth_timestamp="1522987628",
oauth_nonce="ErFKKs"

So, I encode the parameters in this way (Following the instructions):

  • First, the http method:
    POST&

  • Then, the base string URI encoded:
    POST&https%3A%2F%2Fapi.openbankproject.com&

  • Finally, I get the base string after normalizing the request parameters according to Section 3.4.1.3.2:
    POST&https%3A%2F%2Fapi.openbankproject.com&oauth_callback%3Doob%26oauth_consumer_key%3D123%26oauth_nonce%3DErFKKs%26oauth_signature_method%3DHMAC-SHA256%26oauth_timestamp%3D1522987628

  • The secret is created by the concatenation of consumer_secret and oauth_consumer_key in this way:
    456&123 (consumer_secret&oauth_consumer_key)

  • So, if I sign the base string with the secret 456&123 using HMAC-SHA256 I get:
    9a055becbf91403ec0ecc73f574862a7c9e77fcd27650ec5a530fbbfabe1f948

  • And after encoding to Base64 I get:
    OWEwNTViZWNiZjkxNDAzZWMwZWNjNzNmNTc0ODYyYTdjOWU3N2ZjZDI3NjUwZWM1YTUzMGZiYmZhYmUxZjk0OA==

And it doesn't work !!! I cannot get my request token, my signature is wrong.
Am I doing something wrong ? Please, I need help

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the OAuth-1.0-Server tutorial and the POST /oauth/initiate request described in the issue, then compare the documented signature construction with the server's expected OAuth parameters. No repository file or test is named; done means identifying the cause of the rejected signature and documenting a confirmed correction or reproduction.

Written by the indexing model from the issue text.

Assessment

Domain
api, authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.