How do I migrate from basic password authentication to OAuth?
It was revealed today that Twitter will be discontinuing its Basic Authentication for its API; now click on OAuth but I don't know how to use it or its the correct way for me.
All I want to do is post a tweet referencing the last posted post when I delete the post. I am currently sending the credentials for the Twitter account as clear text, which I understand is not secure, but since my site is quite small, this is not a problem, at least for now.
I am using this basic PHP code:
$status = urlencode(stripslashes(urldecode("Test tweet")));
$tweetUrl = 'http://www.twitter.com/statuses/update.xml';
$curl = curl_init();
curl_setopt($curl, CURLOPT_URL, "$tweetUrl");
curl_setopt($curl, CURLOPT_CONNECTTIMEOUT, 2);
curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($curl, CURLOPT_POST, 1);
curl_setopt($curl, CURLOPT_POSTFIELDS, "status=$status");
curl_setopt($curl, CURLOPT_USERPWD, "$username:$password");
$result = curl_exec($curl);
$resultArray = curl_getinfo($curl);
if ($resultArray['http_code'] == 200)
{
curl_close($curl);
$this->redirect("");
}
else
{
curl_close($curl);
echo 'Could not post to Twitter. Please go back and try again.';
}
How do I migrate from the OAuth system? Identity greatly appreciates any tutorials / advice. Thanks in advance.
a source to share
I found this page / script helpful when I implemented OAuth for Twitter: http://www.jaisenmathai.com/blog/2009/04/30/letting-your-users-sign-in-with-twitter-with-oauth /
I'm sure you can get this from the page I linked to, but the code I am using for this class for my page is
$twtrObj=new EpiTwitter($consumer_key, $consumer_secret);
$twtrObj->setToken($tok, $sec);
$status="I just submited new artwork! http://gravityprops.com/dragonart/artwork?action=view&id={$id}";
$update=$twtrObj->post_statusesUpdate(array('status' => $status));
$tmp=$update->response;
with $ tok and $ sec is the token and secret for any particular user that I pull from the database. $ Consumer_key and $ consumer_secret are declared in a separate file that is included (in the same way as on the page I linked to). I put all the files I need in my PHP folder so that only PHP can access it.
a source to share
For starters, why are you sending your account password over plain http://
and not SSL ( https://
)? I would change that right away.
Second: http://oauth.net/documentation/getting-started/
Also read the Twitter documentation, I'm sure they have it somewhere.
a source to share
This example is very good and there are several more Twitter API Wikis .
Edit:
To update you need to ask your users to click the "Login with Twitter" button instead of entering their details. They will be sent to the Twitter OAuth page, and if they allow your app, you should be able to work fine. This way you don't have to deal with any passwords.
a source to share
only OAuth is based on user authorization to access user data, so you cannot exclude user authorization (redirect to Twitter site).
I don't know how, but the auto-tweet plugin for wordpress does whatever you want, if it's a custom application where you want this feature, you can look at its code to see how it is done.
a source to share