(二)网页授权获取用户基本信息

王朝学院·作者佚名  2016-08-28
窄屏简体版  字體: 小  |  中  |  大  |  超大  

在公众号的配置过程中,许多开发者会在菜单中加入HTML5页面,有时在页面内需要访问页面的用户信息,此时就需要网页授权获取用户基本信息

PS:本博文所阐述的微信开发基于Yii2.0框架

1、设置授权回调域名:开发 ---> 接口权限

找到“网页授权获取用户基本信息”,点击后面对应的“修改”,在弹框响应位置填写授权回调域名即可,此处的域名不需要加http:// (关于网页授权回调域名的说明详情可参考公众平台开发者文档)

[flash=500,400]http://s1.knowsky.com/20160211/ocub5zghvap00.png[/flash]

[flash=500,400]http://s1.knowsky.com/20160211/zg3gku52iih00.png[/flash]

2、获取授权

关于OAuth2.0博主参考的是方倍工作室的博文http://www.cnblogs.com/txw1958/p/weixin71-oauth20.html(PS:方倍是一个微信开发大神,其中的微信开发内容还是比较详细的,推荐参考),其中详细剖析了微信官方文档的相关内容,也提供了获取授权的更详细思路和方案。

实际上,获取用户信息的关键在于获取用户的openid。博主想要实现用户点击公众号菜单打开页面即可自动授权,从而针对该用户进行数据库操作,于是有下面两种方式:

(1)利用自定义菜单请求授权页面

自定义菜单后面会单独写一篇博文,在这里先简述一下通过自定义菜单进行授权,该方法需要高级接口权限,且局限于关注公众号的用户直接从菜单进入页面。

1$menu= '{2"button":[3{4"type": "view",5"name": "商城",6"url": "https://open.weixin.QQ.com/connect/oauth2/authorize?appid=xxx&redirect_uri=http://tx.heivr.com/index.php&response_type=code&scope=snsapi_base&state=1#wechat_redirect"7},89{10"name":"快递服务",11"sub_button":[12{13"type":"click",14"name":"发快递",15"key":"exPRess"16},17{18"type":"click",19"name":"快递查询",20"key":"ww"21}22]23},24]25}';

需要授权的view直接在url处填写微信提供的授权请求地址,其中:

appid:填写微信公众平台基本配置中的AppID;redirect_uri:填写授权完成后跳转的页面地址,即自己的html5页面;state:跳转至回调页面所带参数;response_type:网页授权的两种scope,微信官方文档中说明如下:1、以snsapi_base为scope发起的网页授权,是用来获取进入页面的用户的openid的,并且是静默授权并自动跳转到回调页的。用户感知的就是直接进入了回调页(往往是业务页面)2、以snsapi_userinfo为scope发起的网页授权,是用来获取用户的基本信息的。但这种授权需要用户手动同意,并且由于用户同意过,所以无须关注,就可在授权后获取该用户的基本信息。

按照此方法点击“商城”即可接收到返回的openid,继而进行下一步用户信息的获取。

(2)利用JS自动请求授权页面

这个方法相对而言比较笨拙,步骤略复杂,但目前能解决需求还没有研究简化方法,且由于页面的跳转多数情况下访问页面的时间会增加,但相比于前一个方法,该方法可以获取到非关注用户的基本信息。有些程序可能涉及到页面分享,程序没有强制关注但其他用户通过分享直接进入页面也需要记录用户信息,此时可以考虑该方法。(微信开发相关的代码博主封装成工具类调用,这里先贴用到的部分,以后整理完成会全部贴出来并附下载链接)

该方法的思路为:js请求链接获取code ---> 利用code换取openid ---> 得到用户基本信息

a. 编辑配置

为了方便把用到的一些微信参数单独写入一个类,方便修改添加及调用

1<?php2namespace common\tools\wechat;34/**5* 微信请求相关配置类库6*/7classConfigTool {89/**10* 微信配置参数11* @return array 配置参数12*/13publicfunctionsetConfig() {1415//用于验证微信接口配置信息的Token,可以任意填写16$config['token'] = '自己的token';1718//appID19$config['appid'] = '自己的appid';2021//appSecret22$config['secret'] = '自己的secret';2324//回调链接地址25$config['redirect_uri'] = 'http://tx.heivr.com/index.php?';2627//是否以 HTTPS 安全协议访问接口28$config['https_request'] =false;2930//授权作用域,snsapi_base (不弹出授权页面,直接跳转,只能获取用户openid),31// snsapi_userinfo (弹出授权页面,可通过openid拿到昵称、性别、所在地。并且,32// 即使在未关注的情况下,只要用户授权,也能获取其信息)33$config['scope'] = 'snsapi_userinfo';3435//语言36$config['lang'] = 'zh_CN';//zh_CN 简体,zh_TW 繁体,en 英语3738// 微信公众账户授权地址39$config['mp_authorize_url'] = 'https://api.weixin.qq.com/cgi-bin/token';40//微信公众账户js临时票据地址41$config['jsapi_ticket_url'] = 'https://api.weixin.qq.com/cgi-bin/ticket/getticket';42//授权地址43$config['authorize_url'] = 'https://open.weixin.qq.com/connect/oauth2/authorize';44//获取accesstoken 的地址45$config['access_token_url'] = 'https://api.weixin.qq.com/sns/oauth2/access_token';46//刷新 token 的地址47$config['refresh_token_url'] = 'https://api.weixin.qq.com/sns/oauth2/refresh_token';48//获取用户信息地址49$config['userinfo_url'] = 'https://api.weixin.qq.com/sns/userinfo';50//验证access token51$config['valid_token_url'] = 'https://api.weixin.qq.com/sns/auth';52//上传临时素材地址53$config['media_temp_upload_url'] = 'https://api.weixin.qq.com/cgi-bin/media/upload?';54//上传永久素材地址55$config['media_forever_upload_url'] = 'https://api.weixin.qq.com/cgi-bin/material/add_material?';5657return$config;5859}60}

b. https请求工具

1<?php2namespace common\tools;34/**5* https请求相关类库6*/7classHttpsTool {89constTIMEOUT = 5;//设置超时时间1011private$ch;//curl对象1213/**14* 发送curl请求,并获取请求结果15* @param string 请求地址16* @param array 如果是post请求则需要传入请求参数17* @param string 请求方法,get 或者 post, 默认为get18* @param bool 是否以https协议请求19*/20publicfunctionsend_request($requests,$params=null,$method= 'get',$https=true) {21//以get方式提交22if($method== 'get') {23if($params){24$request=$requests.$this->create_url($params);25}else{26$request=$requests;27}28}else{29$request=$requests;30}3132$this->ch = curl_init($request);33curl_setopt($this->ch, CURLOPT_RETURNTRANSFER, 1);//设置不显示结果,储存入变量34curl_setopt($this->ch, CURLOPT_TIMEOUT, self::TIMEOUT);//设置超时限制防止死循环3536// 判断是否以https方式访问37if($https) {38curl_setopt($this->ch, CURLOPT_SSL_VERIFYPEER, 0);//对认证证书来源的检查39curl_setopt($this->ch, CURLOPT_SSL_VERIFYHOST, 0);//从证书中检查SSL加密算法是否存在40}4142if($method== 'post') {//以post方式提交43//curl_setopt($this->ch, CURLOPT_SAFE_UPLOAD, false); //php 5.6文件上传必加内容,5.4不需要44curl_setopt($this->ch, CURLOPT_POST, 1);//发送一个常规的Post请求45curl_setopt($this->ch, CURLOPT_POSTFIELDS,$params);//Post提交的数据包46curl_setopt($this->ch, CURLOPT_RETURNTRANSFER, 1);47}4849$tmpInfo= curl_exec($this->ch);//执行操作50if(curl_errno($this->ch)) {51echo'Errno:'.curl_error($this->ch);//捕抓异常52}53curl_close($this->ch);//关闭CURL会话54//var_dump($tmpInfo);exit;55return$tmpInfo;//返回数据56}5758/**59* 生成url60*/61publicfunctioncreate_url($data) {62$temp= '?';63foreach($dataas$key=>$item) {64$temp=$temp.$key. '=' .$item. '&';65}66returnsubstr($temp, 0, -1);67}68}

关于curl_setopt($this->ch, CURLOPT_SAFE_UPLOAD, false)会在微信图片资源上传博文中详细讲述它出现的心酸史,这里暂时用不到,不做解释

c. 授权基类

1<?php2namespace common\tools\wechat;34usecommon\tools\wechat\ConfigTool;5usecommon\tools\HttpsTool;6/**7* Weixin_oauth 类库8*/9classOauthTool {1011public$conf;1213publicfunction__construct(){14$re=newConfigTool;15$this->conf =$re->setConfig();16}1718/**19* 生成用户授权的地址20* @param string 自定义需要保持的信息21* @param sting 请求的路由22* @param bool 是否是通过公众平台方式认真23*/24publicfunctionauthorize_addr($route,$state='',$mp=false) {2526if($mp) {27$data=[28'appid' =>$this->conf['appid'],29'secret' =>$this->conf['token'],30'grant_type' => 'client_credential'31];32$url=$this->conf['mp_authorize_url'];33}else{34$data=[35'appid' =>$this->conf['appid'],//公众号唯一标识36'redirect_uri' =>urlencode($this->conf['redirect_uri'] .$route),//授权后重定向的回调链接地址37'response_type' => 'code',//返回类型,此处填写code38'scope'=>$this->conf['scope'],//应用授权作用域39'state'=>$state,//重定向后带上state参数,开发者可以填写任意参数40'#wechat_redirect'=>''//直接在微信打开链接,可不填,做页面302重定向时必须带此参数41];42$url=$this->conf['authorize_url'];43}4445$send=newHttpsTool;46//var_dump($url . $send->create_url($data));exit;47return$url.$send->create_url($data);48}4950/**51* 获取 access token52* @param string 用于换取access token的code,微信提供53*/54publicfunctionaccess_token($code) {5556$data=[57'appid' =>$this->conf['appid'],58'secret' =>$this->conf['secret'],59'code' =>$code,60'grant_type' => 'authorization_code'61];62//生成授权url63$url=$this->conf['access_token_url'];6465$send=newHttpsTool;66return$send->send_request($url,$data);67}6869/**70* 获取用户信息71* @param string access token72* @param string 用户的open id73*/74publicfunctionuserinfo($token,$openid) {7576$data=[77'access_token' =>$token,78'openid' =>$openid,79'lang' =>$this->conf['lang']80];81//生成授权url82$url=$this->conf['userinfo_url'];8384$send=newHttpsTool;85return$send->send_request($url,$data);86}8788}

d. 授权基类调用及用户数据处理(在控制器调用前,先对用户数据存入或更新)

1<?php2namespace wechat\controllers\classes;34usecommon\tools\wechat\OauthTool;5usecommon\models\User;6usecommon\tools\EmojiTool;78/**9* 微信用户基本信息获取10*/11classUserinfoClass {1213/**14* 用户授权并获取code15* @return string 用户code16*/17publicfunctiongetCode($route,$state){1819$re=newOauthTool;20$request=$re->authorize_addr($route,$state);21$code=isset($_GET['code']) ?$_GET['code'] : '';2223return[$request,$code];24}2526/**27* 获取用户信息并写入数据库(之后加参数传给code)28*/29publicfunctioninfo($code) {30$re=newOauthTool;31//获取access token32$access=$re->access_token($code);33$token= json_decode($access,true);34//header("Content-type: text/html; charset=gbk");35//获取用户信息36if(count($token) != 2) {37$response=$re->userinfo($token['access_token'],$token['openid']);38$user= json_decode($response,true);39//用户昵称转换40//$user['nickname'] = EmojiTool::emoji_trans($user['nickname']);4142if($model= User::findOne(['openid' =>$user['openid'] ])) {//用户已存在更新数据43$model->attributes =$user;44$model->modify_time =time();45$model->save(false);46}else{//用户不存在写入47$model=newUser;48$model->attributes =$user;49$model->create_time =time();50$model->save(false);51}52}53returnisset($model->id) ?$model->id : '';54}5556}

e. 控制器调用(这里只贴其中一个方法)

1/**2* 产品列表3* @return object 所有可用产品信息4*/5publicfunctionactionIndex(){6//判断页面是否自动刷新7if(isset($_GET['state'])) {8$refresh= 0;9}else{10$refresh= 1;11}1213//获取用户code14$user=newUserinfoClass;15$request=$user->getCode('r=store/index', 1);1617//该用户userid18$userid=$user->info($request[1]);1920$model=newProduct;21$list=$model->find()->where(['status' => 1])->all();2223return$this->render('index',['list' =>$list, 'refresh' =>$refresh, 'userid' =>$userid, 'request' =>$request]);24}

程序要求用户打开产品列表即获取用户信息并存入数据库,其中设计了几个变量作用如下:

$refresh:判断页面是否刷新,由于首次打开页面未进行oauth验证时才自动请求验证,避免反复刷新,这里用回调的state参数作为判断依据且设state=1(若有特定参数需要可将state赋值为所需值);

$request:即为验证请求地址

f. 视图自动刷新

只需要在视图中添加以下js代码即可

1<script type="text/javascript">23//自动请求获取code4$(function(){5varrefresh = <?=$refresh; ?>;6varrequest = '<?= $request[0]; ?>';7if(refresh == 1){8console.log(1);9location =request;10}11});12</script>

特此声明:相关文章均为查阅资料、阅读大神博文后结合实际开发情况遇到的问题整理而成,能找到原博的必会署名,找不到原博而引用的内容还望原博主海涵

 
 
免责声明:本文为网络用户发布,其观点仅代表作者个人观点,与本站无关,本站仅提供信息存储服务。文中陈述内容未经本站证实,其真实性、完整性、及时性本站不作任何保证或承诺,请读者仅作参考,并请自行核实相关内容。
 
© 2005- 王朝網路 版權所有 導航