apache/seatunnel · error · DingTalkConnectorException

GET_SIGN_FAILED

GET_SIGN_FAILED

Error message

Get signature from DinkTalk server failed

What it means

When secret-key signing mode is enabled, getSign computes an HmacSHA256 signature over '<timestamp>\n<secret>' and URL-encodes the base64 result. Any exception (NoSuchAlgorithmException, InvalidKeyException, charset problems) is wrapped as DingTalkConnectorException(GET_SIGN_FAILED, 'Get signature from DinkTalk server failed').

Solutions

  1. Check the secret value: non-empty, correct SEC... key copied from the DingTalk robot 'sign' security setting
  2. Verify the JVM supports HmacSHA256 (default JCE policy); use a standard JDK
  3. Confirm the secret contains no trailing whitespace or newlines from copy-paste

Example fix

// before
secret = "" // empty -> InvalidKeyException
// after
secret = "SECxxxxxxxxxxxxxxxxxxxxxxxx"
Defensive patterns

Strategy: validation

Validate before calling

if (secret == null || secret.trim().isEmpty()) { throw new IllegalStateException("DingTalk secret must be the non-empty SEC... key from the robot sign setting"); }

Try / catch

try { writer.write(row); } catch (DingTalkConnectorException e) { if ("GET_SIGN_FAILED".equals(e.getErrorCode())) log.error("Signature computation failed - check secret/JCE", e); throw e; }

Prevention

When it happens

Trigger: Calling getSign (via sign) when Mac.getInstance("HmacSHA256") or mac.init fails, or the secret is null/empty causing SecretKeySpec construction to throw — any failure while computing the signature for the secured robot webhook.

Common situations: Blank or malformed secret in the sink config (SecretKeySpec rejects empty keys); JVM lacking HmacSHA256 (restricted crypto policies); trailing whitespace/newlines in copy-pasted secrets.

Related errors


AI-assisted analysis of apache/seatunnel@cf67b549a7 (2026-09-10). Data as JSON: /api/errors/b6abff212e87145a. Report an issue: GitHub.

Appendix: source

Thrown at seatunnel-connectors-v2/connector-dingtalk/src/main/java/org/apache/seatunnel/connectors/seatunnel/sink/DingTalkWriter.java:102

                        e);
            }
        }

        public String getUrl() throws IOException {
            Long timestamp = System.currentTimeMillis();
            String sign = getSign(timestamp);
            return url + "&timestamp=" + timestamp + "&sign=" + sign;
        }

        public String getSign(Long timestamp) throws IOException {
            try {
                String stringToSign = timestamp + "\n" + secret;
                Mac mac = Mac.getInstance("HmacSHA256");
                mac.init(new SecretKeySpec(secret.getBytes(StandardCharsets.UTF_8), "HmacSHA256"));
                byte[] signData = mac.doFinal(stringToSign.getBytes(StandardCharsets.UTF_8));
                return URLEncoder.encode(Base64.getEncoder().encodeToString(signData), "UTF-8");
            } catch (Exception e) {
                throw new DingTalkConnectorException(
                        DingTalkConnectorErrorCode.GET_SIGN_FAILED,
                        "Get signature from DinkTalk server failed",
                        e);
            }
        }
    }
}

View on GitHub (pinned to cf67b549a7)