The OAuth process is:
For OAuth authentication, the app (a.k.a OAuth client) redirects the user to the
authorize_urlThis redirects the user to oauth server's webserver, where the user grants the web app access to his/her account
OAuth server redirects the user to the callback url provided by the application (a.k.a oauth client). At this point, the callback came from the OAuth server and hence does not have the session id or session hash. How is the application to determine which user the post-oauth callback is being called for?
I though the way this works is:
When you redirect user to the
authorize_urlyou append certain parameters to the query string?id=xxxWhen the OAuth server redirects to the callback_url provided by the client, one of the parameters with the HTTP message will be the parameter appended to the query string in step 1.
However, this does not seem to work for the OAuth server I am trying to hook into.
Any suggestions?