我自己发现了问题。这是因为 SDK 3.2.2。对于 facebook 更新(来自 API 版本 2.3 的 Changelog):
[Oauth 访问令牌] 格式 - 当您交换 access_token 的代码时返回的 https://www.facebook.com/v2.3/oauth/access_token 的响应格式现在返回有效的 JSON,而不是 URL 编码。此响应的新格式是 {"access_token": {TOKEN}, "token_type":{TYPE}, "expires_in":{TIME}}。我们使此更新符合 RFC 6749 的第 5.1 节。
但 SDK 将响应识别为数组(在 getAccessTokenFromCode 函数中):
$response_params = array();
parse_str($access_token_response, $response_params);
if (!isset($response_params['access_token'])) {
return false;
}
return $response_params['access_token'];
这将无法正确获取用户访问令牌,并且您无法获取用户数据。所以你应该更新这个函数来将数据解析为json:
$response = json_decode($access_token_response);
if (!isset($response->access_token)) {
return false;
}
return $response->access_token;
那么所有的功能都会照常工作。
此外,您必须对setExtendedAccessToken() 进行类似的更改。否则,您的应用将无法扩展访问令牌。下面的代码演示了如何升级功能。
/**
* Extend an access token, while removing the short-lived token that might
* have been generated via client-side flow. Thanks to http://bit.ly/ b0Pt0H
* for the workaround.
*/
public function setExtendedAccessToken() {
try {
// need to circumvent json_decode by calling _oauthRequest
// directly, since response isn't JSON format.
$access_token_response = $this->_oauthRequest(
$this->getUrl('graph', '/oauth/access_token'),
$params = array(
'client_id' => $this->getAppId(),
'client_secret' => $this->getAppSecret(),
'grant_type' => 'fb_exchange_token',
'fb_exchange_token' => $this->getAccessToken(),
)
);
}
catch (FacebookApiException $e) {
// most likely that user very recently revoked authorization.
// In any event, we don't have an access token, so say so.
return false;
}
if (empty($access_token_response)) {
return false;
}
//Version 2.2 and down (Deprecated). For more info, see http://stackoverflow.com/a/43016312/114558
// $response_params = array();
// parse_str($access_token_response, $response_params);
//
// if (!isset($response_params['access_token'])) {
// return false;
// }
//
// $this->destroySession();
//
// $this->setPersistentData(
// 'access_token', $response_params['access_token']
// );
//Version 2.3 and up.
$response = json_decode($access_token_response);
if (!isset($response->access_token)) {
return false;
}
$this->destroySession();
$this->setPersistentData(
'access_token', $response->access_token
);
}