在heroku上通过omniauth登录的Facebook无效

时间:2017-07-17 16:48:19

标签: ruby-on-rails facebook ruby-on-rails-4 heroku omniauth-facebook

我使用Rails创建了一个具有Facebook登录功能的应用程序,它完全适用于localhost,但现在它不能在Heroku上运行。这似乎是每个人都会遇到的常见问题,但过去的问题和其他文章都没有帮助。

error image

以上链接转到错误图像。它应该来自Heroku而不是Facebook,因为我在处理Stripe时看到了同样的错误。在此错误开始困扰我之前,Facebook发出了另一个错误Can't Load URL: The domain of this URL isn't included in the app's domains. To be able to load this URL, add all domains and subdomains of your app to the App Domains field in your app settings.,但是通过将Heroku网址添加到Facebook应用页面来解决这个错误。

我做了figaro heroku:set -e production因此在Heroku中设置了应用密钥和密码。

以下是我文件中的一些代码;

配置/初始化/ devise.rb

config.omniauth :facebook, ENV["facebook_app_id"], ENV["facebook_app_secret"], scope: 'email', info_fields: 'email,name', secure_image_url: true

应用程序/模型/ user.rb

def self.from_omniauth(auth)
  where(provider: auth.provider, uid: auth.uid).first_or_create do |user|
    user.email = auth.info.email
    user.password = Devise.friendly_token[0,20]
    user.name = auth.info.name   # assuming the user model has a name
    user.image = "http://graph.facebook.com/#{auth.uid}/picture?type=large" # assuming the user model has an image
    # If you are using confirmable and the provider(s) you use validate emails,
    # uncomment the line below to skip the confirmation emails.
    # user.skip_confirmation!
  end
end

控制器/用户/ omniauth_callback_controller.rb

class Users::OmniauthCallbacksController < Devise::OmniauthCallbacksController
  def facebook
    # You need to implement the method below in your model (e.g. app/models/user.rb)
    @user = User.from_omniauth(request.env["omniauth.auth"])

    if @user.persisted?
      sign_in_and_redirect @user, :event => :authentication #this will throw if @user is not activated
      set_flash_message(:notice, :success, :kind => "Facebook") if is_navigational_format?
    else
      session["devise.facebook_data"] = request.env["omniauth.auth"]
      redirect_to new_user_registration_url
    end
  end

  def failure
    redirect_to root_path
  end
end

heroku日志

2017-07-17T15:33:54.234171+00:00 app[web.1]: Started GET "/users/auth/facebook/callback?code=AQCoKbzr4 ///// 00703" for 150.116.22.144 at 2017-07-17 15:33:54 +0000
2017-07-17T15:33:54.236011+00:00 app[web.1]: I, [2017-07-17T15:33:54.235951 #4]  INFO -- omniauth: (facebook) Callback phase initiated.
2017-07-17T15:33:54.360053+00:00 app[web.1]: Processing by Users::OmniauthCallbacksController#facebook as HTML
2017-07-17T15:33:54.360097+00:00 app[web.1]:   Parameters: {"code"=>"AQCoKbzr4nv6c7BEpM ///// 86c27a00703"}
2017-07-17T15:33:54.371557+00:00 app[web.1]:   User Load (1.8ms)  SELECT  "users".* FROM "users" WHERE "users"."provider" = $1 AND "users"."uid" = $2  ORDER BY "users"."id" ASC LIMIT 1  [["provider", "facebook"], ["uid", "102081518247"]]
2017-07-17T15:33:54.581790+00:00 heroku[router]: at=info method=GET path="/users/auth/facebook/callback?code=AQCoK ///// a00703" host=xxxxxxx-xxxx-xxxxx.herokuapp.com request_id=93945-1199-417e-8d98-ede264cb fwd="150.116.22.144" dyno=web.1 connect=1ms service=350ms status=500 bytes=1754 protocol=https
2017-07-17T15:33:54.578410+00:00 app[web.1]: Completed 500 Internal Server Error in 218ms (ActiveRecord: 3.0ms)
2017-07-17T15:33:54.579175+00:00 app[web.1]: 
2017-07-17T15:33:54.579178+00:00 app[web.1]: RuntimeError (redirection forbidden: http://graph.facebook.com/102087018247/picture?type=large -> https://scontent.xx.fbcdn.net/v/t1.0-1/p200x200/13064_10202475740292_410664266178542_n.jpg?oh=ef118e9d947604c9c7055a92e2&oe=5A02F8B4):
2017-07-17T15:33:54.579178+00:00 app[web.1]:   app/models/user.rb:18:in `block in from_omniauth'
2017-07-17T15:33:54.579179+00:00 app[web.1]:   app/models/user.rb:14:in `from_omniauth'
2017-07-17T15:33:54.579180+00:00 app[web.1]:   app/controllers/users/omniauth_callbacks_controller.rb:4:in `facebook'
2017-07-17T15:33:54.579180+00:00 app[web.1]: 
2017-07-17T15:33:54.579181+00:00 app[web.1]:

我不知道Heroku日志中的RuntimeError表示...任何线索或建议都会受到赞赏。

2 个答案:

答案 0 :(得分:0)

明确表示您已将Facebook开发者控制台中的生产应用程序域列入白名单。

我通常从我的默认应用程序设置一个子测试应用程序,测试应用程序有自己的密钥并为他们设置ENV并且localhost被列入白名单。这样开发就更容易了

然后在您的应用程序和Heroku中为生产应用程序设置ENV,并将Heroku域列入白名单。确保您的回调包含Heroku生产域,与您列入白名单的域匹配

然后在推送到Heroku之后迁移Heroku数据库(这个经常适用于我)

heroku run rake db:migrate

顺便提一下您访问图片的方式与我完成的方式不同。

user.remote_avatar_url = auth.info.image 

如果这不起作用,请告诉我,我已经在Heroku上设置了一些Facebook登录。

答案 1 :(得分:0)

您遇到重定向错误,因为图片网址会将用户重定向到另一个网址。当将http重定向到https时,open-uri存在限制。

在错误消息中,您可以看到此网址:http://graph.facebook.com/102087018247/picture?type=large将被重定向到https://scontent.xx.fbcdn.net/v/t1.0-1/p200x200/13064_10202475740292_410664266178542_n.jpg?oh=ef118e9d947604c9c7055a92e2&oe=5A02F8B4

您可以通过在图片网址中用https替换http来解决此问题

"https://graph.facebook.com/#{auth.uid}/picture?type=large"

或使用这种方式:

user.remote_image_url = auth.info.image.gsub(/\Ahttp:/, "https")