justauth/JustAuth · error · AuthException

${errcode}

${errcode}

Error message

${errmsg}

What it means

AuthWeChatOpenRequest.checkResponse guards WeChat Open Platform (开放平台) website-app token endpoints: if the response JSON contains `errcode`, JustAuth throws AuthException(errcode, errmsg) — the numeric code on the exception is WeChat's own errcode. It runs on both the access-token fetch and the refresh flow (both routed through getToken).

Solutions

  1. Look up e.getCode() in the WeChat global errcode table and fix the matching config (IP whitelist, secret, code freshness).
  2. For 40030: persist the NEW refresh_token returned by each refresh() call — WeChat open-platform refresh tokens are single-use and rotating.
  3. Add the server egress IP to the open-platform app's web-domain/IP whitelist and verify DNS-level egress (containers/NAT often present a different IP).
  4. Ensure each authorization code is exchanged once, immediately after redirect.
Defensive patterns

Strategy: retry

Validate before calling

// persist rotated refresh tokens; validate presence before refresh
if (StringUtils.isEmpty(old.getRefreshToken())) {
    throw new IllegalStateException("WeChat Open: refresh_token missing, re-auth required");
}

Try / catch

try {
    AuthResponse<AuthToken> r = openRequest.refresh(old);
} catch (AuthException e) {
    if (e.getCode() == 40030 || e.getCode() == 40029) {
        redirect(openRequest.authorize(newState())); // refresh/code dead → re-consent
    } else if (e.getCode() == 40164) {
        throw new ConfigurationException("whitelist egress IP in WeChat Open console", e);
    } else throw e;
}

Prevention

When it happens

Trigger: WeChat Open Platform OAuth failing: invalid code (40029), appsecret mismatch (40125), IP not whitelisted (40164), invalid refresh_token (40030) after the web-app's refresh token was consumed or expired, or component-app style misconfiguration (api unauthorized, 61004).

Common situations: Using a website app's appId/secret from the open platform but the server IP was never whitelisted; refresh token already used (WeChat refresh tokens rotate) and the old one replayed from cache; appid under a third-party platform without completing the component authorization.

Related errors


AI-assisted analysis of justauth/JustAuth@694bbf1b01 (2026-08-14). Data as JSON: /api/errors/b25fd97408399e84. Report an issue: GitHub.

Appendix: source

Thrown at src/main/java/me/zhyd/oauth/request/AuthWeChatOpenRequest.java:86

            .build();
    }

    @Override
    public AuthResponse<AuthToken> refresh(AuthToken oldToken) {
        return AuthResponse.<AuthToken>builder()
            .code(AuthResponseStatus.SUCCESS.getCode())
            .data(this.getToken(refreshTokenUrl(oldToken.getRefreshToken())))
            .build();
    }

    /**
     * 检查响应内容是否正确
     *
     * @param object 请求响应内容
     */
    private void checkResponse(JSONObject object) {
        if (object.containsKey("errcode")) {
            throw new AuthException(object.getIntValue("errcode"), object.getString("errmsg"));
        }
    }

    /**
     * 获取token,适用于获取access_token和刷新token
     *
     * @param accessTokenUrl 实际请求token的地址
     * @return token对象
     */
    private AuthToken getToken(String accessTokenUrl) {
        String response = new HttpUtils(config.getHttpConfig()).get(accessTokenUrl).getBody();
        JSONObject accessTokenObject = JSONObject.parseObject(response);

        this.checkResponse(accessTokenObject);

        return AuthToken.builder()
            .accessToken(accessTokenObject.getString("access_token"))
            .refreshToken(accessTokenObject.getString("refresh_token"))

View on GitHub (pinned to 694bbf1b01)