├── Twitter-Auth-React-Client ├── .gitignore ├── README.md ├── package-lock.json ├── package.json ├── public │ ├── favicon.ico │ ├── index.html │ └── manifest.json └── src │ ├── App.css │ ├── App.js │ ├── App.test.js │ ├── assets │ └── img │ │ └── spinner.gif │ ├── components │ ├── AuthPage.js │ ├── Home.js │ ├── SignIn.js │ └── Spinner.js │ ├── index.css │ ├── index.js │ ├── logo.svg │ └── serviceWorker.js └── Twitter-Auth-React-Server ├── .gitignore ├── package-lock.json ├── package.json └── server.js /Twitter-Auth-React-Client/.gitignore: -------------------------------------------------------------------------------- 1 | # See https://help.github.com/articles/ignoring-files/ for more about ignoring files. 2 | 3 | # dependencies 4 | /node_modules 5 | /.pnp 6 | .pnp.js 7 | 8 | # testing 9 | /coverage 10 | 11 | # production 12 | /build 13 | 14 | # misc 15 | .DS_Store 16 | .env.local 17 | .env.development.local 18 | .env.test.local 19 | .env.production.local 20 | 21 | npm-debug.log* 22 | yarn-debug.log* 23 | yarn-error.log* 24 | yarn.lock* 25 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/README.md: -------------------------------------------------------------------------------- 1 | This project was bootstrapped with [Create React App](https://github.com/facebook/create-react-app). 2 | 3 | ## Available Scripts 4 | 5 | In the project directory, you can run: 6 | 7 | ### `npm start` 8 | 9 | Runs the app in the development mode.
10 | Open [http://localhost:3000](http://localhost:3000) to view it in the browser. 11 | 12 | The page will reload if you make edits.
13 | You will also see any lint errors in the console. 14 | 15 | ### `npm test` 16 | 17 | Launches the test runner in the interactive watch mode.
18 | See the section about [running tests](https://facebook.github.io/create-react-app/docs/running-tests) for more information. 19 | 20 | ### `npm run build` 21 | 22 | Builds the app for production to the `build` folder.
23 | It correctly bundles React in production mode and optimizes the build for the best performance. 24 | 25 | The build is minified and the filenames include the hashes.
26 | Your app is ready to be deployed! 27 | 28 | See the section about [deployment](https://facebook.github.io/create-react-app/docs/deployment) for more information. 29 | 30 | ### `npm run eject` 31 | 32 | **Note: this is a one-way operation. Once you `eject`, you can’t go back!** 33 | 34 | If you aren’t satisfied with the build tool and configuration choices, you can `eject` at any time. This command will remove the single build dependency from your project. 35 | 36 | Instead, it will copy all the configuration files and the transitive dependencies (Webpack, Babel, ESLint, etc) right into your project so you have full control over them. All of the commands except `eject` will still work, but they will point to the copied scripts so you can tweak them. At this point you’re on your own. 37 | 38 | You don’t have to ever use `eject`. The curated feature set is suitable for small and middle deployments, and you shouldn’t feel obligated to use this feature. However we understand that this tool wouldn’t be useful if you couldn’t customize it when you are ready for it. 39 | 40 | ## Learn More 41 | 42 | You can learn more in the [Create React App documentation](https://facebook.github.io/create-react-app/docs/getting-started). 43 | 44 | To learn React, check out the [React documentation](https://reactjs.org/). 45 | 46 | ### Code Splitting 47 | 48 | This section has moved here: https://facebook.github.io/create-react-app/docs/code-splitting 49 | 50 | ### Analyzing the Bundle Size 51 | 52 | This section has moved here: https://facebook.github.io/create-react-app/docs/analyzing-the-bundle-size 53 | 54 | ### Making a Progressive Web App 55 | 56 | This section has moved here: https://facebook.github.io/create-react-app/docs/making-a-progressive-web-app 57 | 58 | ### Advanced Configuration 59 | 60 | This section has moved here: https://facebook.github.io/create-react-app/docs/advanced-configuration 61 | 62 | ### Deployment 63 | 64 | This section has moved here: https://facebook.github.io/create-react-app/docs/deployment 65 | 66 | ### `npm run build` fails to minify 67 | 68 | This section has moved here: https://facebook.github.io/create-react-app/docs/troubleshooting#npm-run-build-fails-to-minify 69 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/package.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "client", 3 | "version": "0.1.0", 4 | "private": true, 5 | "dependencies": { 6 | "axios": "^0.19.0", 7 | "gh-pages": "^2.0.1", 8 | "query-string": "^6.8.1", 9 | "react": "^16.8.6", 10 | "react-dom": "^16.8.6", 11 | "react-router-dom": "^5.0.1", 12 | "react-scripts": "3.0.1" 13 | }, 14 | "scripts": { 15 | "start": "set HOST=127.0.0.1&&react-scripts start", 16 | "build": "react-scripts build", 17 | "test": "react-scripts test", 18 | "eject": "react-scripts eject", 19 | "predeploy": "yarn run build", 20 | "deploy": "gh-pages -d build" 21 | }, 22 | "proxy": "http://localhost:8080", 23 | "eslintConfig": { 24 | "extends": "react-app" 25 | }, 26 | "browserslist": { 27 | "production": [ 28 | ">0.2%", 29 | "not dead", 30 | "not op_mini all" 31 | ], 32 | "development": [ 33 | "last 1 chrome version", 34 | "last 1 firefox version", 35 | "last 1 safari version" 36 | ] 37 | } 38 | } 39 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/public/favicon.ico: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/syedashar1/3-legged-oauth/6b9e4fc1a6d1d5bd606de952a9976166e9b6a22a/Twitter-Auth-React-Client/public/favicon.ico -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/public/index.html: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 12 | 13 | 22 | React App 23 | 24 | 25 | 26 |
27 | 37 | 38 | 39 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/public/manifest.json: -------------------------------------------------------------------------------- 1 | { 2 | "short_name": "React App", 3 | "name": "Create React App Sample", 4 | "icons": [ 5 | { 6 | "src": "favicon.ico", 7 | "sizes": "64x64 32x32 24x24 16x16", 8 | "type": "image/x-icon" 9 | } 10 | ], 11 | "start_url": ".", 12 | "display": "standalone", 13 | "theme_color": "#000000", 14 | "background_color": "#ffffff" 15 | } 16 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/App.css: -------------------------------------------------------------------------------- 1 | .App { 2 | text-align: center; 3 | } 4 | 5 | .App-logo { 6 | animation: App-logo-spin infinite 20s linear; 7 | height: 40vmin; 8 | pointer-events: none; 9 | } 10 | 11 | .App-header { 12 | min-height: 100vh; 13 | display: flex; 14 | flex-direction: column; 15 | align-items: center; 16 | justify-content: center; 17 | } 18 | 19 | .App-link { 20 | color: #61dafb; 21 | } 22 | 23 | @keyframes App-logo-spin { 24 | from { 25 | transform: rotate(0deg); 26 | } 27 | to { 28 | transform: rotate(360deg); 29 | } 30 | } 31 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/App.js: -------------------------------------------------------------------------------- 1 | import React from "react"; 2 | import { BrowserRouter as Router, Route, Switch } from "react-router-dom"; 3 | import "./App.css"; 4 | 5 | import SignIn from "./components/SignIn"; 6 | import AuthPage from "./components/AuthPage"; 7 | import Home from "./components/Home"; 8 | 9 | function App() { 10 | return ( 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | ); 19 | } 20 | 21 | export default App; 22 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/App.test.js: -------------------------------------------------------------------------------- 1 | import React from 'react'; 2 | import ReactDOM from 'react-dom'; 3 | import App from './App'; 4 | 5 | it('renders without crashing', () => { 6 | const div = document.createElement('div'); 7 | ReactDOM.render(, div); 8 | ReactDOM.unmountComponentAtNode(div); 9 | }); 10 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/assets/img/spinner.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/syedashar1/3-legged-oauth/6b9e4fc1a6d1d5bd606de952a9976166e9b6a22a/Twitter-Auth-React-Client/src/assets/img/spinner.gif -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/components/AuthPage.js: -------------------------------------------------------------------------------- 1 | import React, { useEffect } from "react"; 2 | import Spinner from "./Spinner"; 3 | import axios from "axios"; 4 | import qs from "query-string"; 5 | 6 | export default function SignIn(props) { 7 | useEffect(() => { 8 | // gets the returned query 9 | const query = qs.parse(props.location.search, { ignoreQueryPrefix: true }); 10 | 11 | // check to see if returned oauth_token equals our saved oauthRequestToken 12 | if (query.oauth_token === localStorage.getItem("oauthRequestToken")) { 13 | // makes call to callback endpoint(on our server) with the needed params 14 | axios 15 | .get( 16 | `/callback/${localStorage.getItem( 17 | "oauthRequestToken" 18 | )}/${localStorage.getItem("oauthRequestTokenSecret")}/${ 19 | query.oauth_verifier 20 | }` 21 | ) 22 | .then(response => { 23 | if (response.data.oauthAccessToken) { 24 | //check to see if oauthAccessToken is returned 25 | // if returned, check to verify 26 | axios 27 | .get( 28 | `/verify/${response.data.oauthAccessToken}/${ 29 | response.data.oauthAccessTokenSecret 30 | }` 31 | ) 32 | .then(res => { 33 | const { user } = res.data; 34 | const keys = response.data; 35 | 36 | const userInfo = { 37 | accessToken: keys.oauthAccessToken, 38 | secret: keys.oauthAccessTokenSecret, 39 | user_id: user.id_str, 40 | screen_name: user.screen_name, 41 | photo: user.profile_image_url_https.replace("_normal", "") 42 | }; 43 | 44 | // and send user info to /home route 45 | props.history.push({ 46 | pathname: "/home", 47 | state: { 48 | user: userInfo 49 | } 50 | }); 51 | }); 52 | } 53 | }) 54 | .catch(err => { 55 | alert("authentication error"); 56 | props.history.push({ 57 | pathname: "/" 58 | }); 59 | }); 60 | } else { 61 | alert("authentication error"); 62 | // authentication error 63 | props.history.push({ 64 | pathname: "/" 65 | }); 66 | } 67 | }, [props.location.search, props.history]); 68 | return ( 69 |
70 | 71 |

Authenticating...

72 |
73 | ); 74 | } 75 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/components/Home.js: -------------------------------------------------------------------------------- 1 | import React, { useState, useEffect } from "react"; 2 | 3 | export default function Home(props) { 4 | const [user, setUser] = useState({}); 5 | console.log(props); 6 | useEffect(() => { 7 | // if Home page is loaded directly 8 | if (!props.location.state) { 9 | alert("an error occured"); 10 | props.history.push("/"); 11 | } else { 12 | setUser(props.location.state.user); 13 | } 14 | }, [props.location.state, props.history]); //equivalent of componentDidMmount lifecycle method 15 | 16 | const logout = () => { 17 | // logout function 18 | setUser({}); 19 | alert("user logged out"); 20 | props.history.push("/"); 21 | }; 22 | 23 | return ( 24 |
25 | {user.name} 26 |

Welcome {user.screen_name}!

27 | 28 |
29 | ); 30 | } 31 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/components/SignIn.js: -------------------------------------------------------------------------------- 1 | import React, { useState } from "react"; 2 | import Spinner from "./Spinner"; 3 | import axios from "axios"; 4 | 5 | export default function SignIn() { 6 | const [loading, setLoading] = useState(false); 7 | const startAuth = () => { 8 | setLoading(true); 9 | axios 10 | .get("http://localhost:8080/start-auth") 11 | .then(res => { 12 | if (res.data.redirectUrl) { 13 | localStorage.setItem( 14 | "oauthRequestTokenSecret", 15 | res.data.oauthRequestTokenSecret 16 | ); 17 | localStorage.setItem("oauthRequestToken", res.data.oauthRequestToken); 18 | window.location.href = res.data.redirectUrl; 19 | } 20 | }) 21 | .catch(err => { 22 | setLoading(false); 23 | alert("auth error", err); 24 | }); 25 | }; 26 | return ( 27 |
28 |

Twitter 3 Legged Authentication

29 | {loading && } 30 | {!loading && } 31 |
32 | ); 33 | } 34 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/components/Spinner.js: -------------------------------------------------------------------------------- 1 | import React from 'react'; 2 | import spinner from '../assets/img/spinner.gif'; 3 | 4 | export default () => { 5 | return ( 6 |
7 | Loading... 12 |
13 | ); 14 | }; 15 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/index.css: -------------------------------------------------------------------------------- 1 | body { 2 | margin: 0; 3 | font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", "Roboto", "Oxygen", 4 | "Ubuntu", "Cantarell", "Fira Sans", "Droid Sans", "Helvetica Neue", 5 | sans-serif; 6 | -webkit-font-smoothing: antialiased; 7 | -moz-osx-font-smoothing: grayscale; 8 | } 9 | 10 | code { 11 | font-family: source-code-pro, Menlo, Monaco, Consolas, "Courier New", 12 | monospace; 13 | } 14 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/index.js: -------------------------------------------------------------------------------- 1 | import React from 'react'; 2 | import ReactDOM from 'react-dom'; 3 | import './index.css'; 4 | import App from './App'; 5 | import * as serviceWorker from './serviceWorker'; 6 | 7 | ReactDOM.render(, document.getElementById('root')); 8 | 9 | // If you want your app to work offline and load faster, you can change 10 | // unregister() to register() below. Note this comes with some pitfalls. 11 | // Learn more about service workers: https://bit.ly/CRA-PWA 12 | serviceWorker.unregister(); 13 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/logo.svg: -------------------------------------------------------------------------------- 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Client/src/serviceWorker.js: -------------------------------------------------------------------------------- 1 | // This optional code is used to register a service worker. 2 | // register() is not called by default. 3 | 4 | // This lets the app load faster on subsequent visits in production, and gives 5 | // it offline capabilities. However, it also means that developers (and users) 6 | // will only see deployed updates on subsequent visits to a page, after all the 7 | // existing tabs open on the page have been closed, since previously cached 8 | // resources are updated in the background. 9 | 10 | // To learn more about the benefits of this model and instructions on how to 11 | // opt-in, read https://bit.ly/CRA-PWA 12 | 13 | const isLocalhost = Boolean( 14 | window.location.hostname === 'localhost' || 15 | // [::1] is the IPv6 localhost address. 16 | window.location.hostname === '[::1]' || 17 | // 127.0.0.1/8 is considered localhost for IPv4. 18 | window.location.hostname.match( 19 | /^127(?:\.(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)){3}$/ 20 | ) 21 | ); 22 | 23 | export function register(config) { 24 | if (process.env.NODE_ENV === 'production' && 'serviceWorker' in navigator) { 25 | // The URL constructor is available in all browsers that support SW. 26 | const publicUrl = new URL(process.env.PUBLIC_URL, window.location.href); 27 | if (publicUrl.origin !== window.location.origin) { 28 | // Our service worker won't work if PUBLIC_URL is on a different origin 29 | // from what our page is served on. This might happen if a CDN is used to 30 | // serve assets; see https://github.com/facebook/create-react-app/issues/2374 31 | return; 32 | } 33 | 34 | window.addEventListener('load', () => { 35 | const swUrl = `${process.env.PUBLIC_URL}/service-worker.js`; 36 | 37 | if (isLocalhost) { 38 | // This is running on localhost. Let's check if a service worker still exists or not. 39 | checkValidServiceWorker(swUrl, config); 40 | 41 | // Add some additional logging to localhost, pointing developers to the 42 | // service worker/PWA documentation. 43 | navigator.serviceWorker.ready.then(() => { 44 | console.log( 45 | 'This web app is being served cache-first by a service ' + 46 | 'worker. To learn more, visit https://bit.ly/CRA-PWA' 47 | ); 48 | }); 49 | } else { 50 | // Is not localhost. Just register service worker 51 | registerValidSW(swUrl, config); 52 | } 53 | }); 54 | } 55 | } 56 | 57 | function registerValidSW(swUrl, config) { 58 | navigator.serviceWorker 59 | .register(swUrl) 60 | .then(registration => { 61 | registration.onupdatefound = () => { 62 | const installingWorker = registration.installing; 63 | if (installingWorker == null) { 64 | return; 65 | } 66 | installingWorker.onstatechange = () => { 67 | if (installingWorker.state === 'installed') { 68 | if (navigator.serviceWorker.controller) { 69 | // At this point, the updated precached content has been fetched, 70 | // but the previous service worker will still serve the older 71 | // content until all client tabs are closed. 72 | console.log( 73 | 'New content is available and will be used when all ' + 74 | 'tabs for this page are closed. See https://bit.ly/CRA-PWA.' 75 | ); 76 | 77 | // Execute callback 78 | if (config && config.onUpdate) { 79 | config.onUpdate(registration); 80 | } 81 | } else { 82 | // At this point, everything has been precached. 83 | // It's the perfect time to display a 84 | // "Content is cached for offline use." message. 85 | console.log('Content is cached for offline use.'); 86 | 87 | // Execute callback 88 | if (config && config.onSuccess) { 89 | config.onSuccess(registration); 90 | } 91 | } 92 | } 93 | }; 94 | }; 95 | }) 96 | .catch(error => { 97 | console.error('Error during service worker registration:', error); 98 | }); 99 | } 100 | 101 | function checkValidServiceWorker(swUrl, config) { 102 | // Check if the service worker can be found. If it can't reload the page. 103 | fetch(swUrl) 104 | .then(response => { 105 | // Ensure service worker exists, and that we really are getting a JS file. 106 | const contentType = response.headers.get('content-type'); 107 | if ( 108 | response.status === 404 || 109 | (contentType != null && contentType.indexOf('javascript') === -1) 110 | ) { 111 | // No service worker found. Probably a different app. Reload the page. 112 | navigator.serviceWorker.ready.then(registration => { 113 | registration.unregister().then(() => { 114 | window.location.reload(); 115 | }); 116 | }); 117 | } else { 118 | // Service worker found. Proceed as normal. 119 | registerValidSW(swUrl, config); 120 | } 121 | }) 122 | .catch(() => { 123 | console.log( 124 | 'No internet connection found. App is running in offline mode.' 125 | ); 126 | }); 127 | } 128 | 129 | export function unregister() { 130 | if ('serviceWorker' in navigator) { 131 | navigator.serviceWorker.ready.then(registration => { 132 | registration.unregister(); 133 | }); 134 | } 135 | } 136 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Server/.gitignore: -------------------------------------------------------------------------------- 1 | # See https://help.github.com/articles/ignoring-files/ for more about ignoring files. 2 | 3 | # dependencies 4 | /node_modules 5 | .env -------------------------------------------------------------------------------- /Twitter-Auth-React-Server/package.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "backend", 3 | "version": "0.0.0", 4 | "private": true, 5 | "scripts": { 6 | "start": "node server.js", 7 | "server": "nodemon server.js" 8 | }, 9 | "dependencies": { 10 | "cookie-parser": "~1.4.3", 11 | "cors": "^2.8.5", 12 | "debug": "~2.6.9", 13 | "dotenv": "^8.0.0", 14 | "express": "~4.16.0", 15 | "http-errors": "~1.6.2", 16 | "jade": "~1.11.0", 17 | "morgan": "~1.9.0", 18 | "nodemon": "^1.19.1", 19 | "oauth": "^0.9.15" 20 | } 21 | } 22 | -------------------------------------------------------------------------------- /Twitter-Auth-React-Server/server.js: -------------------------------------------------------------------------------- 1 | require('dotenv').config() 2 | const express = require('express'); 3 | const cors = require('cors') 4 | const app = express(); 5 | const oauth = require('oauth') 6 | const universalAppKey = 'oV1SSwjZ4aPQprOWbp9TtKDZ0'; 7 | const universalAppSecret = 'CxIPgD3blZnrLCq0QgLoeUOReieQ4Z6gkH6suzmTNQseWK4vSQ'; 8 | const consumer = new oauth.OAuth( 9 | "https://twitter.com/oauth/request_token", "https://twitter.com/oauth/access_token", 10 | universalAppKey, universalAppSecret, "1.0A", "http://127.0.0.1:3000/auth-page", "HMAC-SHA1"); 11 | 12 | app.use(cors()); 13 | 14 | app.use(express.json()); 15 | app.use(express.urlencoded({ extended: false })); 16 | 17 | 18 | 19 | app.get('/start-auth', (req, res) => { 20 | consumer.getOAuthRequestToken(function(error, oauthRequestToken, oauthRequestTokenSecret, results){ 21 | if (error) { 22 | console.log(error) 23 | res.status(500).send({error:"Error getting OAuth request token : " + error}); 24 | 25 | } else { 26 | console.log("oauthRequestToken "+oauthRequestToken); 27 | console.log("oauthRequestTokenSecret "+oauthRequestTokenSecret); 28 | res.status(200).send({redirectUrl: "https://twitter.com/oauth/authorize?oauth_token="+oauthRequestToken, 29 | oauthRequestToken: oauthRequestToken, 30 | oauthRequestTokenSecret: oauthRequestTokenSecret 31 | }) 32 | } 33 | }); 34 | }) 35 | 36 | app.get( 37 | "/callback/:oauthRequestToken/:oauthRequestTokenSecret/:oauth_verifier", 38 | (req, res) => { 39 | console.log("oauthRequestToken "+req.params.oauthRequestToken); 40 | console.log("oauthRequestTokenSecret "+req.params.oauthRequestTokenSecret); 41 | console.log("oauth_verifier "+req.params.oauth_verifier); 42 | 43 | consumer.getOAuthAccessToken(req.params.oauthRequestToken, req.params.oauthRequestTokenSecret, req.params.oauth_verifier, function(error, oauthAccessToken, oauthAccessTokenSecret, results) { 44 | if (error) { 45 | res.status(500).send({error :"Error getting OAuth access token : " + error + "[" + oauthAccessToken + "]" + "[" + oauthAccessTokenSecret + "]" + "[" + results + "]"}); 46 | } else { 47 | res.status(200).send({oauthAccessToken: oauthAccessToken, oauthAccessTokenSecret: oauthAccessTokenSecret}) 48 | } 49 | }); 50 | }) 51 | 52 | app.get( 53 | "/verify/:oauthAccessToken/:oauthAccessTokenSecret", (req, res) => { 54 | 55 | consumer.get("https://api.twitter.com/1.1/account/verify_credentials.json", req.params.oauthAccessToken, req.params.oauthAccessTokenSecret, function (error, data, response) { 56 | if (error) { 57 | console.log(error) 58 | res.status(500).send({error: "authentication error"}); 59 | } else { 60 | const parsedData = JSON.parse(data); 61 | res.status(200).send({user: parsedData}); 62 | } 63 | }); 64 | 65 | }) 66 | 67 | app.listen(process.env.PORT || 8080, () => { 68 | console.log('listening at port 8080'); 69 | }); 70 | module.exports = app; 71 | --------------------------------------------------------------------------------