Home Backend Development PHP Tutorial WeChat account binding

WeChat account binding

Aug 08, 2016 am 09:30 AM
nbsp openid quot signature

Original address: http://hello1010.com/bind-wechat/

Two-dimensional bar code/QR code (2-dimensional bar code) is a specific geometric figure that is printed on a plane ( Black and white graphics distributed in a two-dimensional direction record data symbol information; in coding, the concepts of "0" and "1" bit streams that form the basis of the computer's internal logic are cleverly used, and several binary numbers are used. Geometric shapes represent text numerical information, and are automatically read through image input devices or photoelectric scanning devices to achieve automatic information processing

In recent years, QR codes have been particularly widely used. WeChat’s promotion and application of QR codes can be said to be like a duck in water, including WeChat QR code payment, WeChat QR code login, WeChat QR code business cards, etc. It can be said that QR codes have become an important link between online and offline in O2O. Brother Xiao Ma also said that "QR code is a key entry point online and offline."

Now many websites have established their own complete user account system. In the era of WeChat for all, it is necessary to consider developing and operating WeChat public accounts, not to follow the trend, but to facilitate users, because WeChat provides O2O A good solution, and more importantly, WeChat has a benign and constantly improving ecological chain.

When a user follows a WeChat official account, there will be some interactions. During the interaction, it may be necessary to obtain the user's identity information (corresponding to the account information on the website), such as placing an order in the official account, querying the order, etc. So now the question comes: For the same user, how do we establish the corresponding relationship between the WeChat official account user (openid) and the website user (userid). This process is called binding.


To simplify the discussion, I summarized the following two scenarios:

1. The user has registered as our website user, but has not yet followed our WeChat public Number;
2. The user has not registered, but has followed our WeChat official account.

For the above two situations, we will discuss them separately below.

Scenario 1

The user has registered as our website user, but has not yet followed our WeChat official account. Here, the user needs to log in first on the website, and then provide a binding entry in an appropriate place, such as in personal settings. The binding process is as follows:


You need to use WeChat’s QR code generation function here: Generate a QR code with parameters

About WeChat QR code, the official document says this :

There are currently two types of QR codes, namely temporary QR codes and permanent QR codes. The former has an expiration time, up to 1800 seconds, but can generate a larger number, and the latter has no expiration time. , the number is small (currently the parameters only support 1--100000). The two QR codes are respectively suitable for account binding, user source statistics and other scenarios.

Obviously, it is more appropriate for us to use temporary QR codes. This can be generated every time the user refreshes the page.

Since the QR code can contain the scene value (scene_id), when the user scans the QR code with the scene value, the WeChat server will push the scene value to our own server. After we get the scene value , you can do verification and binding logic. Note: Generating a QR code requires a certified service number.

A complete binding process should be like this:

①The user logs in to the webpage and clicks "Bind WeChat Account";
②Use the WeChat interface in the background to generate a QR code link and return it to the front-end display , and establish the corresponding relationship between scene value A and the user;
③The user scans the QR code and clicks to follow the WeChat public account (if you have already followed it, jump directly to ④);
④The background receives the scene value A pushed by the WeChat server;
⑤The background queries the corresponding user ID based on the scene value A (depending on the corresponding relationship established in ②);
⑥Establish the corresponding relationship between the user userid and the WeChat user openid;
⑦Push "Binding successful" to the user's WeChat client " prompt;
⑧ Notify the front page that the binding has been completed, refresh the page, and return some WeChat account information. Complete binding.

Among them, in ②, "Establish the corresponding relationship between scene value A and the user", because the user is already logged in, so when the user clicks "Bind WeChat account", we can assign a temporary scene value A in the background The relationship with the user ID. For websites with a small number of users, you can directly use apc in php to cache and set an expiration time (same as the expiration time of the temporary QR code).

In

⑧, since http does not have a push mechanism, the simplest method is to poll to check whether the binding has been completed, and then refresh the page after the binding is completed.

After the binding is completed, when the user interacts with our WeChat official account, the corresponding userid can be found based on the openid, which completes the identity recognition. The previously mentioned order placement and order inquiry are all achievable.

The entire binding process is not complicated, and there is not much technical difficulty in implementing it. The most important thing is the idea.

Scenario 2

Scenario 2, the operation is slightly complicated for the user because it requires the user to complete the login/registration on the WeChat client web page. Therefore, if the registration process is too complicated and cumbersome, it is not recommended to use it.

Process:


The above binding process integrates the registration process, so it looks more complicated. It’s not too difficult to implement. Let’s focus on security issues, because binding accounts involves user information security. Consider two issues:

1. How to prevent links from being forged

The login/registration link needs to be generated by our own server and cannot be forged by others. You can refer to WeChat's verification server address for validity. So a relatively secure login link can be like this:

http://api.hello1010.com/wechat/login.html?openid=x1&signature=x2×tamp=x3&nonce=x4&echostr&=x5

Verify signature Code:

<code><span>private function checkSignature()
{
    $signature = $_GET["signature"];
    $timestamp = $_GET["timestamp"];
    $nonce = $_GET["nonce"];    

    $token = TOKEN;
    $tmpArr = array($token, $timestamp, $nonce);
    sort($tmpArr, SORT_STRING);
    $tmpStr = implode( $tmpArr );
    $tmpStr = sha1( $tmpStr );
    if( $tmpStr == $signature ){
        return true;
    }else{
        return false;
    }
}
</span></code>
Copy after login

The token value can be the same as the one in the backend of your WeChat official account, or you can change it. It is recommended to change it to a safer one.

2. How to ensure that openid is trustworthy

Consider this scenario: User A enters the login page, copies the login link to the browser, replaces openid with user B’s openid, and uses user A’s account and password Log in. This binds user A's userid and user B's openid together, which is obviously unsafe.

There are many solutions, such as encrypting openid. When the encryption method is kept confidential, users cannot forge the encrypted openid. If you do not want to encrypt the openid, you can establish the corresponding relationship between the openid and the signature on the server side when generating the link. If the user tampered with the openid, the verification will not pass.

Remember, never trust the information sent by the client.

Extended Application

After completing the binding, we can make some simple applications. For example, the company needs to hold an offline roadshow event, which requires registration and sign-in to participate.

This is a typical O2O example that can be implemented using WeChat. The process is as follows:


Among them, the "binding user sub-process" is the process in scenario two. The interaction of registration will not be described here, as each business is different.

For a user who has completed binding, all he needs to do to participate in an event is to register through WeChat and then scan the QR code to sign in. The experience is quite smooth.

If you have any questions, please feel free to communicate with me!


The above introduces WeChat account binding, including the relevant aspects. I hope it will be helpful to friends who are interested in PHP tutorials.

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

Solution: Your organization requires you to change your PIN Solution: Your organization requires you to change your PIN Oct 04, 2023 pm 05:45 PM

The message "Your organization has asked you to change your PIN" will appear on the login screen. This happens when the PIN expiration limit is reached on a computer using organization-based account settings, where they have control over personal devices. However, if you set up Windows using a personal account, the error message should ideally not appear. Although this is not always the case. Most users who encounter errors report using their personal accounts. Why does my organization ask me to change my PIN on Windows 11? It's possible that your account is associated with an organization, and your primary approach should be to verify this. Contacting your domain administrator can help! Additionally, misconfigured local policy settings or incorrect registry keys can cause errors. Right now

How to adjust window border settings on Windows 11: Change color and size How to adjust window border settings on Windows 11: Change color and size Sep 22, 2023 am 11:37 AM

Windows 11 brings fresh and elegant design to the forefront; the modern interface allows you to personalize and change the finest details, such as window borders. In this guide, we'll discuss step-by-step instructions to help you create an environment that reflects your style in the Windows operating system. How to change window border settings? Press + to open the Settings app. WindowsI go to Personalization and click Color Settings. Color Change Window Borders Settings Window 11" Width="643" Height="500" > Find the Show accent color on title bar and window borders option, and toggle the switch next to it. To display accent colors on the Start menu and taskbar To display the theme color on the Start menu and taskbar, turn on Show theme on the Start menu and taskbar

How to change title bar color on Windows 11? How to change title bar color on Windows 11? Sep 14, 2023 pm 03:33 PM

By default, the title bar color on Windows 11 depends on the dark/light theme you choose. However, you can change it to any color you want. In this guide, we'll discuss step-by-step instructions for three ways to change it and personalize your desktop experience to make it visually appealing. Is it possible to change the title bar color of active and inactive windows? Yes, you can change the title bar color of active windows using the Settings app, or you can change the title bar color of inactive windows using Registry Editor. To learn these steps, go to the next section. How to change title bar color in Windows 11? 1. Using the Settings app press + to open the settings window. WindowsI go to "Personalization" and then

OOBELANGUAGE Error Problems in Windows 11/10 Repair OOBELANGUAGE Error Problems in Windows 11/10 Repair Jul 16, 2023 pm 03:29 PM

Do you see "A problem occurred" along with the "OOBELANGUAGE" statement on the Windows Installer page? The installation of Windows sometimes stops due to such errors. OOBE means out-of-the-box experience. As the error message indicates, this is an issue related to OOBE language selection. There is nothing to worry about, you can solve this problem with nifty registry editing from the OOBE screen itself. Quick Fix – 1. Click the “Retry” button at the bottom of the OOBE app. This will continue the process without further hiccups. 2. Use the power button to force shut down the system. After the system restarts, OOBE should continue. 3. Disconnect the system from the Internet. Complete all aspects of OOBE in offline mode

How to enable or disable taskbar thumbnail previews on Windows 11 How to enable or disable taskbar thumbnail previews on Windows 11 Sep 15, 2023 pm 03:57 PM

Taskbar thumbnails can be fun, but they can also be distracting or annoying. Considering how often you hover over this area, you may have inadvertently closed important windows a few times. Another disadvantage is that it uses more system resources, so if you've been looking for a way to be more resource efficient, we'll show you how to disable it. However, if your hardware specs can handle it and you like the preview, you can enable it. How to enable taskbar thumbnail preview in Windows 11? 1. Using the Settings app tap the key and click Settings. Windows click System and select About. Click Advanced system settings. Navigate to the Advanced tab and select Settings under Performance. Select "Visual Effects"

Display scaling guide on Windows 11 Display scaling guide on Windows 11 Sep 19, 2023 pm 06:45 PM

We all have different preferences when it comes to display scaling on Windows 11. Some people like big icons, some like small icons. However, we all agree that having the right scaling is important. Poor font scaling or over-scaling of images can be a real productivity killer when working, so you need to know how to customize it to get the most out of your system's capabilities. Advantages of Custom Zoom: This is a useful feature for people who have difficulty reading text on the screen. It helps you see more on the screen at one time. You can create custom extension profiles that apply only to certain monitors and applications. Can help improve the performance of low-end hardware. It gives you more control over what's on your screen. How to use Windows 11

10 Ways to Adjust Brightness on Windows 11 10 Ways to Adjust Brightness on Windows 11 Dec 18, 2023 pm 02:21 PM

Screen brightness is an integral part of using modern computing devices, especially when you look at the screen for long periods of time. It helps you reduce eye strain, improve legibility, and view content easily and efficiently. However, depending on your settings, it can sometimes be difficult to manage brightness, especially on Windows 11 with the new UI changes. If you're having trouble adjusting brightness, here are all the ways to manage brightness on Windows 11. How to Change Brightness on Windows 11 [10 Ways Explained] Single monitor users can use the following methods to adjust brightness on Windows 11. This includes desktop systems using a single monitor as well as laptops. let's start. Method 1: Use the Action Center The Action Center is accessible

How to Fix Activation Error Code 0xc004f069 in Windows Server How to Fix Activation Error Code 0xc004f069 in Windows Server Jul 22, 2023 am 09:49 AM

The activation process on Windows sometimes takes a sudden turn to display an error message containing this error code 0xc004f069. Although the activation process is online, some older systems running Windows Server may experience this issue. Go through these initial checks, and if they don't help you activate your system, jump to the main solution to resolve the issue. Workaround – close the error message and activation window. Then restart the computer. Retry the Windows activation process from scratch again. Fix 1 – Activate from Terminal Activate Windows Server Edition system from cmd terminal. Stage – 1 Check Windows Server Version You have to check which type of W you are using

See all articles