如何在ColdFusion网站实现Steam登录按钮及解决签名验证失败问题
网站实现「使用Steam登录」按钮的正确方式?
我正在开发一个游戏相关网站,需要获取用户的Steam ID,打算采用常见的「使用Steam登录」按钮来处理用户认证。原以为操作简单,实际却遇到了诸多困难。
我已经注册了Steam API密钥,某旧论坛帖子指引我查看官方文档,但该文档并未描述认证流程或具体调用方式,网上也找不到太多清晰易懂的相关资料。
我原本预想的登录流程如下:
- 用户在我的页面看到「使用Steam登录」的链接
- 用户点击链接后跳转到我的服务器页面,该页面通过API密钥调用Steam API获取Steam页面的URL,并重定向用户至该页面
- 用户在Steam页面授权网站获取其信息,随后被重定向至我的网站回调页面,携带用户数据或用于获取数据的令牌
我原本期望文档能展示该流程所需的Postman API调用示例,但并未找到,因此怀疑自己对流程的理解有误。
请问在网站上实现「使用Steam登录」按钮的正确方式是什么?
编辑/更新
我构造了从我的网站跳转至Steam的链接,该链接可实现登录并成功跳转至我的回调页面:
https://steamcommunity.com/openid/login?openid.ns=http%3A%2F%2Fspecs%2Eopenid%2Enet%2Fauth%2F2%2E0&openid.mode=checkid_setup&openid.return_to=https%3A%2F%2FmySite%2Ecom%2FauthCallback%2Ecfm?serverName=shadygrove&openid.realm=https%3A%2F%2FmySite%2Ecom&openid.ns.sreg=http%3A%2F%2Fopenid%2Enet%2Fextensions%2Fsreg%2F1%2E1&openid.claimed_id=http%3A%2F%2Fspecs%2Eopenid%2Enet%2Fauth%2F2%2E0%2Fidentifier%5Fselect&openid.identity=http%3A%2F%2Fspecs%2Eopenid%2Enet%2Fauth%2F2%2E0%2Fidentifier%5Fselect
随后我尝试通过以下代码验证数字签名,但结果始终显示无效:
<cfset openid_response = "openid.ns=#url.openid.ns#&openid.mode=#url.openid.mode#&openid.op_endpoint=#url.openid.op_endpoint#&openid.claimed_id=#url.openid.claimed_id#&openid.identity=#url.openid.identity#&openid.return_to=#url.openid.return_to#&openid.response_nonce=#url.openid.response_nonce#&openid.assoc_handle=#url.openid.assoc_handle#&openid.signed=#url.openid.signed#&openid.sig=#url.openid.sig#"> <!-- Calculate the expected signature --> <cfset expected_signature = hmac( openid_response, application.steamKey, "HmacSHA1", "UTF-8" )> <!-- Compare the calculated signature with the received one --> <cfif expected_signature eq url.openid.sig> <cfoutput>Authentication is valid.</cfoutput> <cfelse> <cfoutput>Authentication is NOT valid.</cfoutput> </cfif>
我尝试了约10种构造openid_response的方式,包括:
- 使用完整查询字符串
- 仅使用openid.signed中列出的字段
- 按URL中出现的顺序使用所有openid字段
找到的另一篇文档细节不足,我甚至不确定自己使用的算法是否正确。
内容的提问来源于stack exchange,提问作者Nicholas
相关产品推荐
相关产品推荐

