2015-01-09 37 views
0

在Facebook登錄視圖的用戶可以拒絕權限。或許,這被拒絕的權限影響到應用程序的功能(你可以少做的事情與此應用程序,因爲有些數據是無法訪問)Omniauth Facebook的:重新請求被拒權限

我想提醒用戶並重新問權限。但我看不出有什麼是Omniauth-Facebook的方式。在Facebook documentation顯示來完成,這是增加一個參數來請求登錄調用方式:auth_type=rerequest

https://www.facebook.com/dialog/oauth? 
    client_id={app-id}& 
    redirect_uri={redirect-uri}& 
    auth_type=rerequest& 
    scope=email 

我還沒有看到這樣做的方式直接與Omniauth席力圖召從「身份驗證/ Facebook的/這個網址回調」由我自己檢查的權限後,但我得到以下錯誤,當用戶重新接受許可,不得以新的登錄:

ERROR -- omniauth: (facebook) Authentication failure! invalid_credentials: OmniAuth::Strategies::OAuth2::CallbackError, csrf_detected | CSRF detected 
OmniAuth::Strategies::OAuth2::CallbackError: csrf_detected | CSRF detected 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/failure_endpoint.rb:25:in `raise_out!' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/failure_endpoint.rb:20:in `call' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/failure_endpoint.rb:12:in `call' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/strategy.rb:475:in `fail!' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-oauth2-1.2.0/lib/omniauth/strategies/oauth2.rb:73:in `callback_phase' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-facebook-1.6.0/lib/omniauth/strategies/facebook.rb:71:in `callback_phase' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/strategy.rb:227:in `callback_call' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/strategy.rb:184:in `call!' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/strategy.rb:164:in `call' 
    /home/ciro/.rvm/gems/ruby-2.1.3/gems/omniauth-1.2.2/lib/omniauth/builder.rb:59:in `call' 

這是我的‘auth /中的Facebook /回調’

on get do 
    on 'auth/facebook/callback' do 
    on param(:code) do |code| 
     email = req.env['omniauth.auth']['info']['email'] 

     if email.nil? or email.empty? 
     res.redirect "https://www.facebook.com/dialog/oauth?client_id=#{ENV['APP_ID']}&redirect_uri=http://localhost:9292/auth/facebook/callback&auth_type=rerequest&scope=email" 
     end 
    end 
    end 
end 

回答

1

的解決方案是通過在OmniAuth請求的參數:

if email.nil? or email.empty? 
    res.redirect "/auth/facebook?scope=email" 
end