I am using Amazon SP api with generated Java SDK. My test-application is checking the orders and also the delivery address. According to Amazon, this should be a restricted operation. But at the moment, I can get the information without the usage of RDT. I tried to use RDT as shown below but it is not working.
// Build orders-api
OrdersV0Api ordersApi = new OrdersV0Api.Builder()
.awsAuthenticationCredentials(awsAuthenticationCredentials)
.lwaAuthorizationCredentials(lwaAuthorizationCredentials)
.awsAuthenticationCredentialsProvider(awsAuthenticationCredentialsProvider)
.endpoint("https://sellingpartnerapi-eu.amazon.com")
.build();
List<String> orderStatuses = new ArrayList<String>();
orderStatuses.add(OrderStatusEnum.UNSHIPPED.getValue());
Calendar cal = Calendar.getInstance();
cal.add(Calendar.DATE, -3);
SimpleDateFormat sdf = new SimpleDateFormat("yyyy-MM-dd'T'HH:mm:ssXX");
sdf.setTimeZone(TimeZone.getTimeZone("UTC"));
String tmp = sdf.format(new Date());
try {
// Get orders
GetOrdersResponse respOrders = ordersApi.getOrders(Marketplaces.getAllMarketplaces(), sdf.format(cal.getTime()), null, null, null, orderStatuses, null, null, null, null, 100, null, null, null);
OrderList orders = respOrders.getPayload().getOrders();
Order ord = orders.get(0);
// Restricted Data Token
RestrictedResource rr = new RestrictedResource();
rr.setMethod(MethodEnum.GET);
rr.setPath("/orders/v0/orders/" + ord.getAmazonOrderId() + "/address");
CreateRestrictedDataTokenRequest req = new CreateRestrictedDataTokenRequest();
req.addRestrictedResourcesItem(rr);
TokensApi tokensApi = new TokensApi.Builder()
.awsAuthenticationCredentials(awsAuthenticationCredentials)
.lwaAuthorizationCredentials(lwaAuthorizationCredentials)
.awsAuthenticationCredentialsProvider(awsAuthenticationCredentialsProvider)
.endpoint("https://sellingpartnerapi-eu.amazon.com")
.build();
CreateRestrictedDataTokenResponse resp3 = tokensApi.createRestrictedDataToken(req);
String token = resp3.getRestrictedDataToken();
// Add token to Header ?
ordersApi.getApiClient().addDefaultHeader("x-amz-access-token", token);
// Get delivery adress
GetOrderAddressResponse respAdress = ordersApi.getOrderAddress(ord.getAmazonOrderId());
Address adr = respAdress.getPayload().getShippingAddress();
} catch (ApiException e) {
e.printStackTrace();
}
When I execute this, I am getting this error: "message": "The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.
It seems like only setting x-amz-access-token is not the right operation to add the RDP. But I also can not see any other operation on ordersApi or ordersApi.getApiClient that seems to be the right one. And also it is unclear to me, why it is working when I just completely not use tokens-api at all.