Beispiel #1
0
<?php

global $user;
$snow_form = true;
$this->load_template('header_oauth.php');
if (isset($_GET['oauth_token']) && $_GET['oauth_token'] != '') {
    require_once $C->INCPATH . 'classes/class_oauth.php';
    $oauth_client = new OAuth($_GET['oauth_token']);
} else {
    echo 'Missing request token.';
    $snow_form = false;
}
if (isset($_POST['submit'])) {
    $oauth_client->set_variable('consumer_key', $oauth_client->get_field_in_table('oauth_request_token', 'consumer_key', 'request_token', $_GET['oauth_token']));
    $err = true;
    if ($_POST['submit'] == 'Deny') {
        $app_name = $oauth_client->get_field_in_table('applications', 'name', 'app_id', $oauth_client->get_value_in_consumer_key('app_id'));
        ?>
			<p style='margin-bottom: 50px; width: auto; text-align: center;'>
				You've denied <b><?php 
        echo $app_name;
        ?>
</b> access to interact with your account!
			</p>
			<?php 
    } elseif ($_POST['submit'] == 'Allow') {
        $err = false;
        $user_id = $user->id;
    } elseif ($_POST['submit'] == 'Submit') {
        $user->logout();
        $user->login($_POST['email'], md5($_POST['password']));
Beispiel #2
0
if ($_SERVER['REQUEST_METHOD'] != 'GET' && $_SERVER['REQUEST_METHOD'] != 'POST') {
    echo 'Invalid request method.';
    exit;
} elseif (isset($_REQUEST['oauth_version']) && $_REQUEST['oauth_version'] != '1.0') {
    echo 'Not supported oauth version.';
    exit;
}
if (isset($_REQUEST['oauth_consumer_key'], $_REQUEST['oauth_nonce'], $_REQUEST['oauth_signature_method'], $_REQUEST['oauth_signature'], $_REQUEST['oauth_timestamp'], $_REQUEST['oauth_token'], $_REQUEST['oauth_verifier'])) {
    require_once $C->INCPATH . 'classes/class_oauth.php';
    $oauth_client = new OAuth($_REQUEST['oauth_consumer_key'], $_REQUEST['oauth_nonce'], $_REQUEST['oauth_signature'], $_REQUEST['oauth_timestamp'], $_REQUEST['oauth_token'], $_REQUEST['oauth_verifier']);
    if (isset($_REQUEST['oauth_version'])) {
        $oauth_client->set_variable('version', '1.0');
    }
    if ($oauth_client->is_valid_access_token_request() && strtolower(urldecode($_REQUEST['oauth_signature_method'])) == 'hmac-sha1' && $oauth_client->decrypt_hmac_sha1()) {
        $oauth_client->set_variable('access_token', $oauth_client->generate_access_token());
        $oauth_client->set_variable('user_id', $oauth_client->get_field_in_table('oauth_request_token', 'user_id', 'request_token', $_REQUEST['oauth_token']));
        if ($oauth_client->set_access_table() && $oauth_client->delete_row_in_table('oauth_request_token', 'request_token', $oauth_client->get_variable('request_token'))) {
            echo 'oauth_token_secret=' . urlencode($oauth_client->get_variable('token_secret'));
            echo '&oauth_token=' . urlencode($oauth_client->get_variable('access_token'));
        } else {
            echo $oauth_client->get_variable('error_msg');
            exit;
        }
    } else {
        echo $oauth_client->there_is_error() ? $oauth_client->get_variable('error_msg') : 'Invalid signature method';
        exit;
    }
} else {
    echo 'Missing OAuth parameters.';
    exit;
}