$params = ['grant_type' => 'password','client_id' => $this->client_id,'client_secret' => $this->client_secret, 'username' => $username,'password' => $password . $security_token];$ch = curl_init('https:xxxxxxxxxxxxxxxxxxxxxxxxx/services/oauth2/token');curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);curl_setopt($ch, CURLOPT_POST, true);curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($params));curl_setopt($ch, CURLOPT_HTTPHEADER, ['Content-Type: application/x-www-form-urlencoded']);curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);$response = curl_exec($ch); $http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE);curl_close($ch);In the login history it tells me that the username and password flow is disabled but I specifically went and enabled it in my domain. I have the proper scope I think. Any ideas why this fails?
It is an Manage External Client Apps if that matters?
3 respostas
Hi ,
OAuth 2.0 Username-Password Flow Blocked by Default in New Orgs
Block Authorization Flows to Improve Security