主题
授权端点(account.sso.authorize)
用于把用户拉起到 VDS 账户授权页,授权成功后回跳并带回 code。
本端点为标准 OAuth 授权端点:无需任何开放平台签名,可直接配置为标准 OAuth 框架(Passport、Spring Security、NextAuth 等)的 authorization_endpoint。
请求地址
标准形式(推荐,无需签名,浏览器直接跳转):
GET /api/proxy/account/sso/authorize- 不携带开放平台凭证访问时,服务端会
302重定向到 VDS 账户授权页,Query 参数原样保留
也可以让前端直跳上游地址(效果等价):
GET https://account.vds.pub/authorize
兼容说明:携带开放平台签名(Authorization: Bearer <开放平台签名> 或 X-Api-Key)的旧请求仍按原有代理方式处理,需要 account.sso.authorize 权限节点。
Query 参数(逐项填写)
client_id:应用 ID(vap_xxxx)redirect_uri:回调地址(必须在应用重定向 URL 列表中)response_type:固定code(当前仅支持该值)scope:openid或profile(推荐profile)state:可选,建议生成随机串
组装授权链接
可按下面顺序组装:
- 固定地址:
https://open-global.vdsentnet.com/api/proxy/account/sso/authorize(或https://account.vds.pub/authorize) - 拼接
client_id=<你的 vap_xxxx> - 拼接
redirect_uri=<URL 编码后的回调地址> - 拼接
response_type=code(固定) - 拼接
scope=openid或scope=profile - 可选拼接
state=<随机串>
示例:
text
https://open-global.vdsentnet.com/api/proxy/account/sso/authorize?client_id=vap_inzba7z2qbhgsk2y&redirect_uri=https%3A%2F%2Fdsv.pub&response_type=code&scope=openid&state=cS2SxD0tcxj4nxNbFlp95dZBIWDKrbMV成功返回
浏览器回跳到:
text
<redirect_uri>?code=AUTH_CODE&state=YOUR_STATE失败返回
浏览器回跳到:
text
<redirect_uri>?error=invalid_request&error_description=...&state=YOUR_STATE