Intuit OpenID Connect, Authorization code returned by the server not working

Viewed 272

I'm trying to implement OpenId Connect for QuickBooks, as they are deprecating in 2019 OAuth1.

In the documentation here, I have first to prepare an authorization request to redirect the user to the Intuit OAUth 2.0 server.

To handle all the process, I use the omniauth strategy gem omniauth-quickbooks-oauth2. Here is the omniauth setup:

Rails.application.config.middleware.use OmniAuth::Builder do
  # Open ID Connect
  provider(
    :quickbooks_oauth2,
    ENV['INTUIT_CLIENT_ID'],
    ENV['INTUIT_CLIENT_SECRET'],
    scope: 'com.intuit.quickbooks.accounting openid profile email phone address',
    sandbox: Rails.env.development?,
  )
end

It generates the following request:

https://appcenter.intuit.com/connect/oauth2?client_id=MYCLIENTID&redirect_uri=http%3A%2F%2Flocalhost%3A3000%2Fauth%2Fquickbooks_oauth2%2Fcallback&response_type=code&scope=com.intuit.quickbooks.accounting+openid+profile+email+phone+address&state=71f636c1097f8d5bf07a66df5ca64ec43800ea90f6bcedca

Once the user grants the access, Intuit redirect to my redirect URL, and after the user authentification, I get the Authorization code from the params to request the tokens.

For this I use the Gem oauth2

oauth_params = {
      :site => "https://appcenter.intuit.com/connect/oauth2",
      :authorize_url => "https://appcenter.intuit.com/connect/oauth2",
      :token_url => "https://oauth.platform.intuit.com/oauth2/v1/tokens/bearer"
    }
client = OAuth2::Client.new(ENV['INTUIT_CLIENT_ID'], ENV['INTUIT_CLIENT_SECRET'], oauth_params)

client.auth_code.get_token(authorization_code,
                                :redirect_uri => 'http://localhost:3000/auth/quickbooks_oauth2/callback',
                                :grant_type => "authorization_code")

I then obtain an error message:

OAuth2::Error: invalid_grant:
{"error":"invalid_grant"}

I checked my call back uri are the same on the Intuit developer portal:

http://localhost:3000/auth/quickbooks_oauth2/callback

When I try my code to obtain the tokens from the authorization code I obtained from the Intuit OAUth2 Playground, it works! Which make me believe the issue may be coming from the implementation of Omniauth, But I'm stucked!

0 Answers
Related