簡體   English   中英

在PHP中簽名Twitter Trend API v1.1請求失敗

[英]Signing Twitter trends API v1.1 request in PHP fails

從Twitter API版本1.1開始, 每個請求都必須通過OAuth 1.0a進行身份驗證和簽名。 在我的PHP項目中,我想使用Twitter Trends API,尤其是我想使用GET Trends / place調用。 因此它是只讀的。 現在,授權有一個很好的Twitter的API文檔的請求在這里 我們了解到,我們必須在HTTP請求中發送一個稱為“ Authorization”的附加標頭,其中包含一個以“ OAuth”開頭的字符串,並包含七個參數:

  1. oauth_consumer_key
  2. oauth_nonce
  3. oauth_signature
  4. oauth_signature_method
  5. oauth_timestamp
  6. 組oauth_token
  7. oauth_version

在這七個參數中,上面提到的第三個參數oauth_signature非常特殊,因為要構建其值,您必須包括所有其他參數以及更多參數,然后對其進行簽名。 同樣, 這里對過程進行了很好的解釋。

注冊我的應用程序並獲取用戶密鑰和機密以及訪問令牌和機密后,我執行了所有這些步驟。 這是我的PHP代碼(當然,我刪除了所有秘密):

    $HTTPmethod = 'GET';
$twitterApiBaseUrl = 'https://api.twitter.com/1.1/trends/place.json';
$twitterApiParams  = 'id=' . $WOEID;
$twitterApiCallUrl = $twitterApiBaseUrl . '?' . $twitterApiParams;

$OAuthConsumerKey = 'eV78fJOOiObfeytAwvWCg';
$OAuthAccessToken = '1116971396-6uc4xOLziLAdiqOfrtKfuRraa2GdCzas9aQX8ZB';
$OAConsumerSecret = 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';
$OATokenSecret    = 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx';

// building the necessary (as of Twitter API v1.1) authorization header
// according to https://dev.twitter.com/docs/auth/authorizing-request
$DST = 'OAuth ';

// 1.: Consumer key
$oaConsumerKeyKey = rawurlencode("oauth_consumer_key");
$oaConsumerKeyVal = rawurlencode($OAuthConsumerKey);
$DST .= $oaConsumerKeyKey . '="' . $oaConsumerKeyVal . '", ';

// 2.: Nonce
$oaNonceKey = rawurlencode("oauth_nonce");
$oaNonceVal = rawurlencode(base64_encode(time()));
$DST .= $oaNonceKey . '="' . $oaNonceVal . '", ';

// 3.: Signature method
$oaSignatureMethodKey = rawurlencode("oauth_signature_method");
$oaSignatureMethodVal = rawurlencode('HMAC-SHA1');
$DST .= $oaSignatureMethodKey . '="' . $oaSignatureMethodVal . '", ';

// 4.: Timestamp
$oaTimestampKey = rawurlencode("oauth_timestamp");
$oaTimestampVal = rawurlencode(time());
$DST .= $oaTimestampKey . '="' . $oaTimestampVal . '", ';

// 5.: Token
$oaTokenKey = rawurlencode("oauth_token");
$oaTokenVal = rawurlencode($OAuthAccessToken);
$DST .= $oaTokenKey . '="' . $oaTokenVal . '", ';

// 6.: Version
$oaVersionKey = rawurlencode("oauth_version");
$oaVersionVal = rawurlencode('1.0');
$DST .= $oaVersionKey . '="' . $oaVersionVal . '", ';

// 7.: Signature
// according to https://dev.twitter.com/docs/auth/creating-signature
$preSignatureBaseString = $twitterApiParams;
$preSignatureBaseString .= '&';
$preSignatureBaseString .= $oaConsumerKeyKey . '=' . $oaConsumerKeyVal;
$preSignatureBaseString .= '&';
$preSignatureBaseString .= $oaNonceKey . '=' . $oaNonceVal;
$preSignatureBaseString .= '&';
$preSignatureBaseString .= $oaSignatureMethodKey . '=' . $oaSignatureMethodVal;
$preSignatureBaseString .= '&';
    $preSignatureBaseString .= $oaTimestampKey . '=' . $oaTimestampVal;     
$preSignatureBaseString .= '&';
$preSignatureBaseString .= $oaTokenKey . '=' . $oaTokenVal;
$preSignatureBaseString .= '&';
$preSignatureBaseString .= $oaVersionKey . '=' .$oaVersionVal;

print "<b>preSignatureBaseString:</b> $preSignatureBaseString<p/>\n";

$signatureBaseString = $HTTPmethod;
$signatureBaseString .= '&';
$signatureBaseString .= rawurlencode($twitterApiBaseUrl);
$signatureBaseString .= '&';
$signatureBaseString .= rawurlencode($preSignatureBaseString);

print "<b>signatureBaseString:</b> $signatureBaseString<p/>\n";

$signingKey = rawurlencode($OAConsumerSecret) . '&' . rawurlencode($OATokenSecret);

$oaSignatureKey = rawurlencode("oauth_signature");
$oaSignatureVal = base64_encode(hash_hmac('sha1', $signatureBaseString, $signingKey));

print "<b>oaSignatureVal:</b> $oaSignatureVal<p/>\n";

$DST .= $oaSignatureKey . '="' . rawurlencode($oaSignatureVal) . '"';

print "<b>DST:</b> $DST<p/>\n";

$header = "User-Agent: MyCoolTwitterTrendsApp\r\n" .
          "Authorization: " . $DST . "\r\n";              
$opts = array(
        'http' => array(
           'method'    => $HTTPmethod,
           'header'    => $header
        ));
print "<b>header:</b> $header<p/>\n";

    $context = stream_context_create($opts);

$twitterApiResponse = file_get_contents($twitterApiCallUrl, false, $context);

$decodedResponse = json_decode($twitterApiResponse);

echo $decodedResponse;

問題是,每次對API的實際調用都會失敗,並顯示“ HTTP / 1.0 401 Unauthorized”錯誤。 誰能告訴我為什么和我在做什么錯? 非常感謝!

不知道這是否是我遇到的相同問題,但是嘗試檢查我的時間戳記是否恰好在1小時前關閉,請弄清楚那是什么!! 節省日光時間

使用此代碼

        $oauth_hash = '';
        $oauth_hash .= 'oauth_consumer_key=YOUR_CONSUMER_KEY&';
        $oauth_hash .= 'oauth_nonce=' . time() . '&';
        $oauth_hash .= 'oauth_signature_method=HMAC-SHA1&';
        $oauth_hash .= 'oauth_timestamp=' . time() . '&';
        $oauth_hash .= 'oauth_token=YOUR_ACCESS_TOKEN&';
        $oauth_hash .= 'oauth_version=1.0';
        $base = '';
        $base .= 'GET';
        $base .= '&';
        $base .= rawurlencode('https://api.twitter.com/1.1/trends/place.json');
        $base .= '&';
        $base .= rawurlencode('id=23424848&'.$oauth_hash);
        $key = '';
        $key .= rawurlencode('YOUR_CONSUMER_SECRET');
        $key .= '&';
        $key .= rawurlencode('YOUR_ACCESS_TOKEN_SECRET');

        $signature = base64_encode(hash_hmac('sha1', $base, $key, true));
        $signature = rawurlencode($signature);
        $oauth_header = '';
        $oauth_header .= 'oauth_consumer_key="YOUR_CONSUMER_KEY", ';
        $oauth_header .= 'oauth_nonce="' . time() . '", ';
        $oauth_header .= 'oauth_signature="' . $signature . '", ';
        $oauth_header .= 'oauth_signature_method="HMAC-SHA1", ';
        $oauth_header .= 'oauth_timestamp="' . time() . '", ';
        $oauth_header .= 'oauth_token="YOUR_ACCESS_TOKEN", ';
        $oauth_header .= 'oauth_version="1.0", ';
        $curl_header = array("Authorization: Oauth {$oauth_header}", 'Expect:');
        $curl_request = curl_init();
        curl_setopt($curl_request, CURLOPT_HTTPHEADER, $curl_header);
        curl_setopt($curl_request, CURLOPT_HEADER, false);
        curl_setopt($curl_request, CURLOPT_URL, 'https://api.twitter.com/1.1/trends/place.json?id=23424848');
        curl_setopt($curl_request, CURLOPT_RETURNTRANSFER, true);
        curl_setopt($curl_request, CURLOPT_SSL_VERIFYPEER, false);
        var_dump(curl_exec($curl_request));
        curl_close($curl_request);

我已修改代碼以從此博客獲取用戶時間表

暫無
暫無

聲明:本站的技術帖子網頁,遵循CC BY-SA 4.0協議,如果您需要轉載,請注明本站網址或者原文地址。任何問題請咨詢:yoyou2525@163.com.

 
粵ICP備18138465號  © 2020-2024 STACKOOM.COM