Problema JWT API DocuSign (Python)

Sep 26 2020

Sembra che abbia problemi a far funzionare correttamente l'autenticazione quando si utilizza il metodo jwt.

Ecco la richiesta costruita per l'autorizzazione con l'applicazione

        uri = api_client.get_authorization_uri(                                                                            
            client_id       = DOCUSIGN_APP_INTEGRATION_KEY,                                                       
            redirect_uri    = WEBHOOK_URL,                                          
            scopes          = ["signature","impersonation"],                                                               
            response_type   = 'code',                                                                                      
        )                                                                                                                  
        uri +="&prompt=login"       

Ed ecco il webhook per ottenere il token

            api_client  = ApiClient(oauth_host_name = settings.DOCUSIGN_OAUTH_HOST_NAME)                                   
                                                                                                                           
            # Get account id for authed user                                                                               
            xyz = api_client.generate_access_token(                                                                        
                client_id           = DOCUSIGN_APP_INTEGRATION_KEY,                                               
                client_secret       = DOCUSIGN_CLIENT_SECRET_KEY,                                                 
                code                = code,                                                                                
            )                                                                                                              
                                                                                                                           
            resp = api_client.get_user_info(access_token = xyz.access_token)                                               
                                                                                                                           
                                                                                     
            acc_id = resp.sub                                                                                     
            base_uri = ''                                                                                                  
            for account in resp.accounts:                                                                                  
                if account.is_default:                                                                                     
                    base_uri = account.base_uri                                                                                   
                    break                                                                                                  
                                                                                                                           
            token = api_client.request_jwt_user_token(                                                                     
                client_id           = DOCUSIGN_APP_INTEGRATION_KEY,                                               
                user_id             = acc_id,                                                                              
                oauth_host_name     = api_client.get_oauth_host_name(),                                                    
                private_key_bytes   = DOCUSIGN_PRIVATE_KEY,                                                       
                expires_in          = 3600,                                                                                
            )
            
            # Save token.access_token, and base_uri for use elsewhere
            ...               

Ho anche provato a utilizzare l'ID account trovato da resp.accounts [0] .account_id (poiché esiste un solo account per l'utente) ma non riesce request_jwt_user_tokencon questo errore

HTTP response body: b'{"error":"invalid_grant","error_description":"user_not_found"}

Funziona tutto bene e bene, ma poi quando provo a creare una busta altrove usando il token in questo modo

    # Setup api client with token                                                                                      
        api_client = ApiClient()                                                                                           
        api_client.host = api_base_path # set to https://demo.docusign.net/restapi                                                                                  
        api_client.set_default_header("Authorization", "Bearer " + token)                                                  
        envelope_api = EnvelopesApi(api_client)                                                                            
                                                                                                                           
        try:                                                                                                               
            envelope_resp = envelope_api.create_envelope(                                                                  
                DOCUSIGN_API_USER_KEY,                                                                            
                envelope_definition=envelope_definition                                                                    
            )                                                                                                              
        except ApiException as e:
            ...                                                                                         
                            

Ricevo questo errore

HTTP response body: b'{"errorCode":"USER_DOES_NOT_BELONG_TO_SPECIFIED_ACCOUNT","message":"The specified User is not a member of the specified Account."}'

Ho anche provato a utilizzare al acc_idposto della chiave degli utenti api durante la creazione della busta, ma questo dà questo errore:

HTTP response body: b'{"errorCode":"PARTNER_AUTHENTICATION_FAILED","message":"The specified Integrator Key was not found or is disabled. Invalid account specified for user."}'

Tutto questo viene fatto tramite la libreria fornita docusign-esignper python.

Non sai bene dove andare da qui, ma qualsiasi aiuto è apprezzato!

Risposte

1 InbarGazit Sep 27 2020 at 03:25

Here is some information that may help.

In DocuSign you have accounts and memberships that are part of the accounts - users. So, a userId is one thing (GUID) and an accountID is another thing (GUID). You can only access envelopes from an account to which you are member. when using JWT, you have to provide the userId to get the access token. The calls are them made by impersonating this user. If you try to access an envelope (or anything) from an account to which said user has no membership - you get the error you got.

Un'ultima cosa, assicurati che tutto sia fatto nella stessa anv. Ciò significa che se Oauth viene eseguito in demo / developer (account-d.docusign.com), le chiamate API vengono effettuate allo stesso env (demo.docusign.net). Se utilizzi account.docusign.com (produzione), le chiamate API devono essere all'URL corretto che NON sarà demo.docusign.net (ma potrebbe essere na3.docusign.net o eu1.docusign.net ecc.)