Quick and simple PHP Twitter login for your site, ideal for your weekend project
github.com
github.com
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, 0);
Those lines disable certificate verification: if I can intercept the connection between this client and Twitter, I can present my own, self-signed certificate and the client will still send requests as if I were twitter.com. This completely defeats the purpose of using SSL for connections.Perhaps I could add an optional setting to include those lines of code...but that's the beauty of open source -- so can you :).
Edit: Pull request created. https://github.com/jmathai/twitter-async/pull/108
Another nitpick: if I'm logged in, and twitterCallback() is called, why is it redirecting me to / ? Perhaps my site is nested deep within a directory structure.
I might add a login button function that will allow you to put the login button anywhere without protecting the page at the same time.
echo "<p>You are logged in as ".$_SESSION['logged_in'].".</p>";
shiver