繁体   English   中英

Facebook访问令牌/登录

[英]Facebook Access Tokens / Login

我正在尝试使用Facebook的OAuth令牌为我的网站编写自定义授权/取消授权脚本。 我可以将令牌发布到数据库中,但是当我删除令牌并刷新页面时,即使我没有单击授权链接,它也会再次发布令牌。

我的authorize.php:

<div class="authorize_btn" style="float:right; margin-top:-35px; padding-right:10px">
<?php 
    $db_conx = mysqli_connect("localhost","root","","test");

    if (mysqli_connect_errno())
    { 
        echo mysqli_connect_error();
        exit();
    }

    $sql    = "SELECT fb_token FROM users";
    $user   = $_SESSION['username'];
    $query  = mysqli_query($db_conx, $sql);
    $row    = mysqli_fetch_array($query); 

    $login = $facebook->getLoginUrl();

    $access_token = $facebook->getAccessToken();

    $fb_token = $row[0];

    if (empty($fb_token))
    {

        $add_user = "<a href='$login'>Add User</a>";
        echo $add_user; 

        if ($add_user)
        {
            $sql = mysqli_query($db_conx, "UPDATE users SET fb_token='$access_token' where username='$user'");
        }

    }
    else 
    {
        echo "<form id='deauth' action='deauth_fb.php' method='post'>";     
        echo "<a href='#' onclick='document.forms[0].submit();'>Deauthorize User</a>";  
        echo "</form>";                                         
    }
?>
</div>

我的deauth_fb.php:

<?php
    session_start();

    include ('inc/facebook.php');
    include ('fbconfig.php');

    $db_conx = mysqli_connect("localhost","root","","test");

    if (mysqli_connect_errno())
    {
        echo mysqli_connect_errno();
        exit();
    }

    $facebook = new Facebook(array(
        'appId'         => APP_ID, 
        'appSecret'     => APP_SECRET, 
    )); 

    $user_session = $_SESSION['username'];
    $delete_sql = mysqli_query($db_conx, "UPDATE users SET fb_token='' where username='$user_session'");


    header('location:home.php');
?>

如果令牌仍然有效,Facebook将刷新该令牌,您应使用官方方式:

https://developers.facebook.com/docs/reference/php/facebook-getLogoutUrl/

那是因为您只是在不注销用户的情况下将fb_token更新为blank

获取注销URL:

$params = array( 'next' => 'http://after_logout.lnk' );
$logout = $facebook->getLogoutUrl($params);

getLogoutURL()采用可选的$params数组,其中包含键和值对:

next →(可选)注销后将用户重定向到的下一个URL(应该是绝对URL)。

参考

暂无
暂无

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM