Problema JWT API DocuSign (Python)
Sembra che abbia problemi a far funzionare correttamente l'autenticazione quando si utilizza il metodo jwt.
Ecco la richiesta costruita per l'autorizzazione con l'applicazione
uri = api_client.get_authorization_uri(
client_id = DOCUSIGN_APP_INTEGRATION_KEY,
redirect_uri = WEBHOOK_URL,
scopes = ["signature","impersonation"],
response_type = 'code',
)
uri +="&prompt=login"
Ed ecco il webhook per ottenere il token
api_client = ApiClient(oauth_host_name = settings.DOCUSIGN_OAUTH_HOST_NAME)
# Get account id for authed user
xyz = api_client.generate_access_token(
client_id = DOCUSIGN_APP_INTEGRATION_KEY,
client_secret = DOCUSIGN_CLIENT_SECRET_KEY,
code = code,
)
resp = api_client.get_user_info(access_token = xyz.access_token)
acc_id = resp.sub
base_uri = ''
for account in resp.accounts:
if account.is_default:
base_uri = account.base_uri
break
token = api_client.request_jwt_user_token(
client_id = DOCUSIGN_APP_INTEGRATION_KEY,
user_id = acc_id,
oauth_host_name = api_client.get_oauth_host_name(),
private_key_bytes = DOCUSIGN_PRIVATE_KEY,
expires_in = 3600,
)
# Save token.access_token, and base_uri for use elsewhere
...
Ho anche provato a utilizzare l'ID account trovato da resp.accounts [0] .account_id (poiché esiste un solo account per l'utente) ma non riesce request_jwt_user_tokencon questo errore
HTTP response body: b'{"error":"invalid_grant","error_description":"user_not_found"}
Funziona tutto bene e bene, ma poi quando provo a creare una busta altrove usando il token in questo modo
# Setup api client with token
api_client = ApiClient()
api_client.host = api_base_path # set to https://demo.docusign.net/restapi
api_client.set_default_header("Authorization", "Bearer " + token)
envelope_api = EnvelopesApi(api_client)
try:
envelope_resp = envelope_api.create_envelope(
DOCUSIGN_API_USER_KEY,
envelope_definition=envelope_definition
)
except ApiException as e:
...
Ricevo questo errore
HTTP response body: b'{"errorCode":"USER_DOES_NOT_BELONG_TO_SPECIFIED_ACCOUNT","message":"The specified User is not a member of the specified Account."}'
Ho anche provato a utilizzare al acc_idposto della chiave degli utenti api durante la creazione della busta, ma questo dà questo errore:
HTTP response body: b'{"errorCode":"PARTNER_AUTHENTICATION_FAILED","message":"The specified Integrator Key was not found or is disabled. Invalid account specified for user."}'
Tutto questo viene fatto tramite la libreria fornita docusign-esignper python.
Non sai bene dove andare da qui, ma qualsiasi aiuto è apprezzato!
Risposte
Here is some information that may help.
In DocuSign you have accounts and memberships that are part of the accounts - users. So, a userId is one thing (GUID) and an accountID is another thing (GUID). You can only access envelopes from an account to which you are member. when using JWT, you have to provide the userId to get the access token. The calls are them made by impersonating this user. If you try to access an envelope (or anything) from an account to which said user has no membership - you get the error you got.
Un'ultima cosa, assicurati che tutto sia fatto nella stessa anv. Ciò significa che se Oauth viene eseguito in demo / developer (account-d.docusign.com), le chiamate API vengono effettuate allo stesso env (demo.docusign.net). Se utilizzi account.docusign.com (produzione), le chiamate API devono essere all'URL corretto che NON sarà demo.docusign.net (ma potrebbe essere na3.docusign.net o eu1.docusign.net ecc.)