如何使用 Reddit 交换访问令牌的代码 API

How to exchange code for access token with Reddit API

我确定这是一个更广泛的问题,不仅适用于 Reddit,但目前我正在尝试用代码交换用户访问令牌,但我不明白如何执行以下步骤:

https://github.com/reddit-archive/reddit/wiki/OAuth2#retrieving-the-access-token

If you didn't get an error and the state value checks out, you may then make a POST request with code to the following URL to retrieve your access token:

https://www.reddit.com/api/v1/access_token

Include the following information in your POST data (NOT as part of the URL)

grant_type=authorization_code&code=CODE&redirect_uri=URI

好吧,我是这样做的:

headers = {
     CLIENT_ID: CLIENT_SECRET,
    }
r = requests.post(
    url="https://www.reddit.com/api/v1/access_token",
    data={
        "grant_type": "authorization_code",
        "code": code,
        "redirect_uri": "http://127.0.0.1:5000/callback"
      },
    headers=headers
  )

我想我在 headers 上失败了,我收到了 429 错误,而且我不认为我已经理解如何正确排列 headers,因为它不清楚在上面解释link.

The "user" is the client_id. The "password" for confidential clients is the client_secret. The "password" for non-confidential clients (installed apps) is an empty string.

CLIENT_IDCLIENT_SECRET 显然是变量,它们是我的 Reddit App 开发凭据。

编辑:

我想到了这个,虽然很恶心,但似乎有效

headers = {
        "User-Agent": "MyApp v1.0",
        "Authorization": "Basic " + str(base64.b64encode(str.encode(f"{CLIENT_ID}:{CLIENT_SECRET}")))[2:-1],
    }

有没有更简洁的写法?

最终答案,使用 Python 请求中的内置方法:

client_auth = requests.auth.HTTPBasicAuth(CLIENT_ID, CLIENT_SECRET)

r = requests.post(
    url="https://www.example.com/api/v1/access_token",
    auth=client_auth,
    data={
        "grant_type": "authorization_code",
        "code": code,
        "redirect_uri": "http://127.0.0.1:5000/callback"
    },
    headers={
        "User-Agent": "MyApp v1.0",
    }
)