Javascript HTTP错误";验证“CSFR错误”;通过Google应用程序脚本使用POST to Todoist API

Javascript HTTP错误";验证“CSFR错误”;通过Google应用程序脚本使用POST to Todoist API,javascript,curl,google-apps-script,oauth,todoist,Javascript,Curl,Google Apps Script,Oauth,Todoist,我正试图从GoogleApps脚本中查询ToDoistAPI中的项目,模拟一个curl帖子 我最初试图使OAuth2工作,但令牌不是持久的,而是选择使用单个API令牌交换有效令牌 使用应用程序脚本,我试图在POST请求时为Todoist的API构造检索任务项的API,我的getToDoIsToken()函数确实在检索有效的令牌响应,但POST命令发出以下403: “error_tag”:“AUTH_CSRF_error”,“error_code”:0,“http_code”:403,“error

我正试图从GoogleApps脚本中查询ToDoistAPI中的项目,模拟一个curl帖子

我最初试图使OAuth2工作,但令牌不是持久的,而是选择使用单个API令牌交换有效令牌

使用应用程序脚本,我试图在POST请求时为Todoist的API构造检索任务项的API,我的
getToDoIsToken()
函数确实在检索有效的令牌响应,但POST命令发出以下403:

“error_tag”:“AUTH_CSRF_error”,“error_code”:0,“http_code”:403,“error_extra”:{“access_type”:“web_session”},“error”:“AUTH_CSRF_error”}

有人能推荐一个解决方案吗?非常感谢,代码如下:

function getTodoistToken() {
  var url = "https://todoist.com/api/access_tokens/migrate_personal_token";
  var data = {
    "client_id": "[my unique client_id]",
    "client_secret": "[my unique client_secret]", 
    "personal_token":"[my API token from Todoist dashboard]", 
    "scope": "data:read"
  };
  var payload = JSON.stringify(data);

  var headers = {
    "Content-Type":"application/json", 
  };

  var options = { 
    "method":"POST",
    "contentType" : "application/json",
    "headers": headers,
    "payload" : payload
  };

  var response = UrlFetchApp.fetch(url, options);
  var json = response.getContentText();
  var data = JSON.parse(json);
  return(data.access_token);  

}

function getTodoistTasks(){
  var apiURL = "https://todoist.com/API/v7/sync";

  var data = {
    "token" : getTodoistToken(),
    "sync_token" : '*',
    "resource_types" : '["items"]'
  };

  var payload = JSON.stringify(data);

  Logger.log(payload);
   var headers = {
     "Content-Type":"application/json", 
   };

  var options = { 
    "method":"POST",
    "contentType" : "application/json",
    "headers": headers,
    "payload" : payload,
    "muteHttpExceptions" : true
  };

  var response = UrlFetchApp.fetch(apiURL, options);

  Logger.log(response.getContentText()); 

}

我已经找到了答案。Todoist API文档有点模棱两可,似乎是围绕POST请求编写的,但要下载(同步)完整的任务列表,一个简单的URL编码的GET请求(如下所示)就可以做到这一点:

function getTodoistTasks(){
  var apiURL = "https://todoist.com/API/v7/sync";
  var queryString = "?token=" + getTodoistTokenRev() + "&sync_token=%27*%27&resource_types=[%22items%22]";

  //Get params
  var fetchParameters = {};
  fetchParameters.method = 'get';
  fetchParameters.contentType = 'x-www-form-urlencoded';
  fetchParameters.muteHttpExceptions = true;

  //make request and return
  var response = UrlFetchApp.fetch(apiURL + queryString, fetchParameters);
  var syncData = JSON.parse(response.getContentText());
  return(syncData);
}

如果有人正在寻找创建项目的示例(本例中是任务),就像我一样,下面是代码(注意,您需要指定一个日期字符串和到期日期,以便它显示在web UI中):

var API_URL = "https://todoist.com/API/v7/sync"
var BASE_QUERY = "?token=" + TOKEN

function addTask() {

//  var taskName = SpreadsheetApp.getUi().prompt('What the task\'s name?')
  var taskName = 'Test 1652'

  var commands = encodeURI(JSON.stringify([{
    "type": "item_add", 
    "temp_id": uuidv4(),
    "uuid": uuidv4(), 
    "args": {
      "content": taskName,
      "date_string": "today",
      "due_date_utc": "2017-12-2T18:00",
    }   
  }]))

  var queryString = BASE_QUERY + '&commands=' + commands

  var options = {
    method: 'post',
    contentType: 'x-www-form-urlencoded',
    muteHttpExceptions: true}

  var response = UrlFetchApp.fetch(API_URL + queryString, options)

  if (response.getResponseCode() !== 200) {
    var content = response.getContentText()
    throw new Error('URL fetch failed: ' + content) 
  }

  var syncData = JSON.parse(response.getContentText())
  return syncData

  // Private Functions
  // -----------------

  function uuidv4() {
    return 'xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx'.replace(/[xy]/g, function(c) {
      var r = Math.random() * 16 | 0, v = c == 'x' ? r : (r & 0x3 | 0x8);
      return v.toString(16);
    });
  }

} // addTask()