Closed (fixed)
Project:
Salesforce Suite
Version:
8.x-4.x-dev
Component:
salesforce_oauth.module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
8 Jan 2021 at 03:34 UTC
Updated:
25 Mar 2021 at 18:24 UTC
Jump to comment: Most recent, Most recent file
Comments
Comment #2
dougvann commentedI feel your pain, Vladimir!
See my workaround for this below in bold type. However, I hope there is a better solution for our shared problem.
Routinely, the D8/SF integration stops working and I discover that authentication has failed.
I go to admin/config/salesforce/authorize/list then select Edit.Re-Auth on the default provider.
I see the form and resubmit it and get "website encountered an error." After checking logs, I see the Guzzle error that Vladimir posted.
WORKAROUND : I create a brand new profile but I use the exact same values. Upon saving the form. I am redirected to test.salesforce.com where I log in and complete the authentication process.
Once authenticated, the clock starts ticking. Will I need to re-authenticate the next day OR the next week or maybe a few hours later?
The auth is not stable and WILL fail within some amount of time. If no one uses the form for a few days, then I get a break.
Maybe I am doing something wrong here OR maybe my client's SF Vendor is doing something that breaks the auth?
Comment #3
onewhocodes commentedI have this same issue doug. We created a new one and literally 2 days later over the weekend it broke again
Comment #4
aaronbaumanI've heard reports of this elsewhere, and have seen it a few times myself, but haven't figured out root cause yet.
One idea: Do you have any mappings set up to pull, so that an API query is issued regularly during cron, and the access token refreshed? Only 2 modules implement hook_cron(), and thereby keep the token refreshed: salesforce_push and salesforce_pull. Of those, only salesforce_pull_cron() is guaranteed to issue an API query: salesforce_push_cron() won't do anything if there's no content that's been modified.
Comment #5
onewhocodes commentedAaron i do believe we do not have anything running on cron we are runnning a contact form which pushes into salesforce. It worked on friday and then broke again.
Comment #6
aaronbaumanWhat is supposed to happen is that, when the API client gets a "access token expired" message from Salesforce, it refreshes the token using the "refresh token" which should be set up to never expire. Something is not working in that process, though I don't know exactly where the breakdown is. Traditional OAuth being so annoying and opaque is one of the big reasons I recommend using JWT OAuth instead.
I'm happy to try and help here, and put in a patch if we can figure out a fix. But I can't reliable recreate this scenario in order to get a handle on it, and don't have time to track it down myself.
Comment #7
onewhocodes commentedI see. We will get our client to look at their sales force set up to see how long the expiry is set for
Comment #8
onewhocodes commentedHi aaron , it looks like they never expire they have set the token to 0 hours which we assume is infinite?
Comment #9
aaronbaumanHere's the relevant bit in RestClient where the access token gets refreshed:
Maybe it should be re-authing on Bad_OAuth_Token in addition to 401?
Comment #10
onewhocodes commentedIts quite possible. We could try updating this section of the code to try it? what would the amend need to be
Comment #11
onewhocodes commentedIve added a die to the rest client , when I try to reauth , it doesn't hit this file at all?
Comment #12
aaronbaumanTry this patch
Comment #13
onewhocodes commentedAaron how do we apply patch files? is there a guide somewhere? we inherited this site from another party.
Comment #14
aaronbaumanReally depends on your setup. The simplest way is to run this command from within the salesforce module directory:
curl https://www.drupal.org/files/issues/2021-01-26/salesforce_oauth-redirect_dance-3191597.patch | git applyComment #15
onewhocodes commentedTo confirm that would be modules/contrib/salesforce/modules or modules/contrib/salesforce
sidenote:
tried locally in each dir , it didn't apply?
Comment #16
vladimirausModified patch to apply. Also trying it on my installation in the next couple of days.
Comment #17
onewhocodes commentedWhat did you do to get this to work? It will not apply at all for me. Just keeps saying 0 changed files
Comment #18
vladimiraus@onewhocodes
git apply -v file.patchComment #19
onewhocodes commentedWe have applied the patch, it worked for one day then we still keep getting faced with the same issue?
Comment #20
onewhocodes commentedHi all
we are now facing a new error after the patch
OAuth\OAuth2\Service\Exception\MissingRefreshTokenException
Comment #21
vladimirausEverything worked after I applied the patch.
I had to reauthenticate and set new authentication method as default.
Comment #22
onewhocodes commentedHey @Vladimir and @Aaron
Do you have any suggestions about
OAuth\OAuth2\Service\Exception\MissingRefreshTokenException
I also deleted all old integrations and set up a new one
Now I have this error ?
Error when connecting to Salesforce. Please check your credentials and try again: cURL error 6: Could not resolve host: sobjects (see https://curl.haxx.se/libcurl/c/libcurl-errors.html)
Comment #23
vladimiraus@onewhocodes Make sureyou reauthenticate and that none other environment is using different OAuth key.
I broke my prod environment by refreshing token on dev,
Comment #24
onewhocodes commentedIf we go to this url
admin/structure/salesforce/mappings/manage/website_contact_form/fields
we see the error Error when connecting to Salesforce. Please check your credentials and try again: cURL error 6: Could not resolve host: sobjects (see https://curl.haxx.se/libcurl/c/libcurl-errors.html)
However the connection said successfully connected something has broken and I have no idea what.
Comment #25
venkatadapa commentedHi @Vladimir @onewhocodes
I am also getting same issue for each site for every environment.
Please check your credentials and try again: cURL error 6: Could not resolve host: sobjects (see https://curl.haxx.se/libcurl/c/libcurl-errors.html)For me, it is working when I re-authenticate (resubmit the form) from url admin/config/salesforce/authorize/edit/oauth_full_sandbox. The issue is resolved, but I had to do the same for all sites in each environment after the code has been deployed to higher environments.
Can this be automated ?
Comment #26
aaronbaumanKeep in mind when changing environments: access and refresh tokens are stored in settings, not config.
If you're changing between salesforce orgs during deploy, your tokens will not be invalid and need to be revoked afterwards.
This can be done in the UI, or via `drush salesforce:revoke-token`
Comment #28
aaronbaumanCommitted. Thanks for everyone's contributions