代码之家  ›  专栏  ›  技术社区  ›  axsuul

有没有办法检查Facebook访问令牌是否仍然有效?

  •  71
  • axsuul  · 技术社区  · 15 年前

    我的网站使用终身访问令牌( offline_access ). 但是,如果用户更改了密码,访问令牌将被重置。在调用Graph API之前,是否有方法检查当前访问令牌是否有效?谢谢你的时间。

    10 回复  |  直到 10 年前
        1
  •  38
  •   Olie    10 年前

    基本上,FB希望你为它投票,或检测到的情况下,重定向用户获得一个重新授权发生。烦人,但官方:

    (旧的、过时的链接。(见下文) https://developers.facebook.com/blog/post/500/

    https://developers.facebook.com/blog/post/2011/05/13/how-to--handle-expired-access-tokens/

        2
  •  72
  •   serg    15 年前

    离线,不发送任何东西到facebook-我不这么认为。最简单的方法可能是将请求发送到:

    https://graph.facebook.com/me?access_token=...
    

    Facebook还支持订阅 real-time 更新,但我不知道如何将它们应用于这种情况。

        3
  •  45
  •   Chaitanya Bharat    13 年前

    https://graph.facebook.com/oauth/access_token_info?client_id=APPID&access_token=xxxxxxxxx
    
        5
  •  4
  •   Nate Totten    15 年前

        6
  •  3
  •   Pavol Golias    8 年前

    我浏览了这些帖子,巴德,我发现非常好的解决方案如下:

    GET graph.facebook.com/debug_token?
        input_token={token-to-inspect}
        &access_token={app_id}|{app_secret}
    

    此请求的响应为您提供了所需的一切:

    • 你的应用程序ID
    • 应用程序名称
    • 过期时间
    • \有效吗 -用于检查的布尔值
    • 用户id -你也可以比较和检查

        7
  •  1
  •   ashraf mohammed    13 年前
            //When user access token expires user must be logged in and renew the access token him self.it is a Facebook policy 
            //you can overcome this by sending email to users who have expired access token.
            //create a table of successful sending to monitor sending process
            //if any failure happened with the user an email is sent to him to ask him to activate there account again.with a link to your subscription page.
            //and here is the code should be written on that page. 
             $app_id = "YOUR_APP_ID";
             $app_secret = "YOUR_APP_SECRET"; 
             $my_url = "YOUR_POST_LOGIN_URL";
    
            // known valid access token stored in a database 
            $access_token = "YOUR_STORED_ACCESS_TOKEN";
    
            $code = $_REQUEST["code"];
    
           // If we get a code, it means that we have re-authed the user 
           //and can get a valid access_token. 
           if (isset($code)) {
             $token_url="https://graph.facebook.com/oauth/access_token?client_id="
               . $app_id . "&redirect_uri=" . urlencode($my_url) 
               . "&client_secret=" . $app_secret 
               . "&code=" . $code . "&display=popup";
             $response = file_get_contents($token_url);
             $params = null;
             parse_str($response, $params);
             $access_token = $params['access_token'];
           }
    
    
           // Attempt to query the graph:
           $graph_url = "https://graph.facebook.com/me?"
             . "access_token=" . $access_token;
           $response = curl_get_file_contents($graph_url);
           $decoded_response = json_decode($response);
    
           //Check for errors 
           if ($decoded_response->error) {
           // check to see if this is an oAuth error:
             if ($decoded_response->error->type== "OAuthException") {
               // Retrieving a valid access token. 
               $dialog_url= "https://www.facebook.com/dialog/oauth?"
                 . "client_id=" . $app_id 
                 . "&redirect_uri=" . urlencode($my_url);
               echo("<script> top.location.href='" . $dialog_url 
              . "'</script>");
            }
            else {
              echo "other error has happened";
            }
          } 
          else {
          // success
            echo("success" . $decoded_response->name);
            echo($access_token);
          }
    
          // note this wrapper function exists in order to circumvent PHP's 
          //strict obeying of HTTP error codes.  In this case, Facebook 
          //returns error code 400 which PHP obeys and wipes out 
          //the response.
          function curl_get_file_contents($URL) {
            $c = curl_init();
            curl_setopt($c, CURLOPT_RETURNTRANSFER, 1);
            curl_setopt($c, CURLOPT_URL, $URL);
            $contents = curl_exec($c);
            $err  = curl_getinfo($c,CURLINFO_HTTP_CODE);
            curl_close($c);
            if ($contents) return $contents;
            else return FALSE;
          }
    
        8
  •  1
  •   demo    7 年前

    离线-这是不可能的

    询问用户是否已授予权限:

    https://graph.facebook.com/{facebook-id}/permissions?access_token={access-token}
    

    如果访问令牌无效,则会给出错误:

    {  
       error:{  
          message:"The access token could not be decrypted",
          type:"OAuthException",
          code:190
       }
    }
    

    否则,它将给出用户已授予的权限列表:

    data:[  
       {  
          installed:1,
          ...... permission list......... 
          bookmarked:1
       }
    ]
    
        9
  •  0
  •   Kevin Cantwell    10 年前

    您可以在此处调试访问令牌: https://developers.facebook.com/tools/debug/accesstoken?version=v2.5&q= {访问令牌}

        10
  •  -6
  •   Jonah Braun    14 年前

    Otto在facebook上的回答似乎是对这个问题的官方回应,但是它使用了直接的PHP而不是SDK,并且使用JS来解决这个问题而不是PHP。如果您使用PHP来检查有效的会话,您通常需要一个PHP方法来确保有效的会话才能继续。

    下面的代码使用graph API检查me对象。如果抛出异常,它将销毁*当前的Facebook会话。

    try{
        $facebook->api('/me');
    }
    catch( FacebookApiException $e ){
        $facebook->destroySession();
    }
    

    这将强制稍后的graph调用实例化一个新的Facebook会话。这至少允许您访问公共数据,以便您可以呈现不需要FB用户权限的页面:

    $facebook->api('/userName');
    

    要重新获得用户访问权限,用户需要登录到您的应用程序(这与登录到Facebook本身是不同的)。您可以使用JS或PHP来实现这一点:

    $facebook->getLoginUrl();
    

    推荐文章