2015-07-22 43 views
2

现在我使用Facebook SDK V5.0 按“使用Facebook登入”后,其自动重定向到“callback.php” 和长寿命的访问令牌应该发出。但是使用Facebook的SDK V5.0但错误尝试出现

每次都会出现此错误。

Facebook SDK returned an error: Cross-site request forgery validation failed. Required param "state" missing. 

,如果您有任何解决方案来解决这个错误 请告诉我。

这里是我的代码:callback.php

<html> 
<meta charset="UTF-8" content="text/html"> 
<?php 

session_start(); 
require_once __DIR__ . '/facebook-php-sdk-v4-5.0-dev/src/Facebook/autoload.php'; 

$fb = new Facebook\Facebook([ 
    'app_id' => '3xxxxxxxxxxxxxxxxxx7', 
    'app_secret' => '0xxxxxxxxxxxxxxxxxxxx7', 
    'default_graph_version' => 'v2.4', 
    ]); 

$helper = $fb->getRedirectLoginHelper(); 

try { 
    $accessToken = $helper->getAccessToken(); 
} catch(Facebook\Exceptions\FacebookResponseException $e) { 
    // When Graph returns an error 
    echo 'Graph returned an error: ' . $e->getMessage(); 
    exit; 

} catch(Facebook\Exceptions\FacebookSDKException $e) { 
    // When validation fails or other local issues 
    echo 'Facebook SDK returned an error: ' . $e->getMessage(); 
    exit; 
} 

if (! isset($accessToken)) { 
    if ($helper->getError()) { 
    header('HTTP/1.0 401 Unauthorized'); 
    echo "Error: " . $helper->getError() . "\n"; 
    echo "Error Code: " . $helper->getErrorCode() . "\n"; 
    echo "Error Reason: " . $helper->getErrorReason() . "\n"; 
    echo "Error Description: " . $helper->getErrorDescription() . "\n"; 
    } else { 
    header('HTTP/1.0 400 Bad Request'); 
    echo 'Bad request'; 
    } 
    exit; 
} 

// Logged in 
echo '<h3>Access Token</h3>'; 
var_dump($accessToken->getValue()); 

// The OAuth 2.0 client handler helps us manage access tokens 
$oAuth2Client = $fb->getOAuth2Client(); 

// Get the access token metadata from /debug_token 
$tokenMetadata = $oAuth2Client->debugToken($accessToken); 
echo '<h3>Metadata</h3>'; 
var_dump($tokenMetadata); 

// Validation (these will throw FacebookSDKException's when they fail) 
$tokenMetadata->validateAppId($config['app_id']); 
// If you know the user ID this access token belongs to, you can validate it here 
//$tokenMetadata->validateUserId('123'); 
$tokenMetadata->validateExpiration(); 

if (! $accessToken->isLongLived()) { 
    // Exchanges a short-lived access token for a long-lived one 
    try { 
    $accessToken = $oAuth2Client->getLongLivedAccessToken($accessToken); 
    } catch (Facebook\Exceptions\FacebookSDKException $e) { 
    echo "<p>Error getting long-lived access token: " . $helper->getMessage() . "</p>\n\n"; 
    exit; 
    } 

    echo '<h3>Long-lived</h3>'; 
    var_dump($accessToken->getValue()); 
} 

$_SESSION['fb_access_token'] = (string) $accessToken; 

// User is logged in with a long-lived access token. 
// You can redirect them to a members-only page. 
//header('Location: https://example.com/members.php'); 
?> 
</html> 

以防万一,我也张贴本。 :login.php中

<html> 
<meta charset="UTF-8" content="text/html"> 
<?php 

session_start(); 
require_once __DIR__ . '/facebook-php-sdk-v4-5.0-dev/src/Facebook/autoload.php'; 


$fb = new Facebook\Facebook([ 
    'app_id' => '3xxxxxxxxxxxxxxxxx7', 
    'app_secret' => '0xxxxxxxxxxxxxxxxxxx7', 
    'default_graph_version' => 'v2.4', 
    ]); 
$helper = $fb->getRedirectLoginHelper(); 

$permissions = ['email']; // Optional permissions 
$loginUrl = $helper->getLoginUrl('http://127.0.0.1:8887/fb/fb-callback.php', $permissions); 

echo '<a href="' . $loginUrl . '">Log in with Facebook!</a>'; 

?> 

</html> 
+0

启用适当的PHP错误报告!在输出完成后调用'session_start'应该会导致错误(除非输出缓冲处于激活状态)。 – CBroe

+0

感谢您告诉我这一点。 –

+0

session_start(); require_once __DIR__。 '/facebook-php-sdk-v4-5.0-dev/src/Facebook/autoload.php'; 你的意思是这段代码对吗?应该重写什么? –

回答

0

我没有得到`跨站点请求伪造...”错误与此代码,就得到了另一个基本误差,这并没有阻止脚本运行。

这里是我做了修复基本的错误的几处修改:

1. Instead of "http://127.0.0.1:8887..." I have used "http://localhost...". (I'm running XAMPP server this might caused error on this one.) 

2. Instead of $config['app_id'] I have used my app id value directly. Like this: 

$app_id = '4xxxxxxxxxxx2'; 

$tokenMetadata->validateAppId($app_id); 

正如我所说的那些错误didnt停止脚本运行,所以你应该检查你的Facebook应用程序面板设置和入门部分。

+0

感谢您的回答。关于“2”,你的意思是什么应用程序ID值直接?你指着哪个? –

+0

您从facebook开发人员网站获得的appid值。在你的情况下,这一个:'3xxxxxxxxxxxxxxxxxx7' – Brian

+0

你是否像这样编码? $ tokenMetadata-> validateAppId($配置[ '3xxxxxxxxxxxx7']); –

相关问题