For the Token-Based method, this is very simple. You only need to compose an XML request, use your API url and Token from Freshbooks - http://developers.freshbooks.com, then use curl to execute the request. You can check out below on how I do it by calling create client and list clients request.
<?php
$apiurl = 'https://sample.freshbooks.com/api/2.1/xml-in';
$token = '<your token here>';
create_client($apiurl, $token);
list_clients($apiurl, $token);
function create_client($apiurl='', $token='') {
$xmldata = "<?xml version=\"1.0\" encoding=\"utf-8\"?>
<request method=\"client.create\">
<client>
<first_name>Jane</first_name>
<last_name>Doe</last_name>
<organization>ABC Corp5</organization>
<email>janedoe@freshbooks.com</email>
</client>
</request>";
$output = xml_request($apiurl, $token, $xmldata);
var_dump($output);
}
function list_clients($apiurl='', $token='') {
$xmldata = "<?xml version=\"1.0\" encoding=\"utf-8\"?>
<request method=\"client.list\">
<folder>active</folder>
</request>";
$output = xml_request($apiurl, $token, $xmldata);
var_dump($output);
}
function xml_request($apiurl='', $token='', $xmldata='') {
$output = '';
system("curl -u $token:X $apiurl -d '$xmldata'", $output);
return $output;
}
?>
For the OAuth method, this is pretty much complex than the Token-Based method. Please see below on the implementation I did. I also use plaintext signature method, the same method I used on my previous post - Dropbox OAuth API Integration on PHP
The first and important thing we need to have is the App key and App secret which we will use for authentication. I believed you will need an approval from Freshbooks to be able to get this information.
Once we have these credentials, we are now ready to start the coding part.
To start with, since we will be posting request to API url, I created a function in doing post request. We will be using this for request token and access token process.
function post_request($url='', $param='') {
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url);
curl_setopt($ch, CURLOPT_VERBOSE, 1);
// disable ssl verification
curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, FALSE);
curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, FALSE);
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($ch, CURLOPT_POST, 1);
// submit post request parameters
curl_setopt($ch, CURLOPT_POSTFIELDS, $param);
// getting response from server
$output = curl_exec($ch);
return $output;
}
Now we can start requesting for a token. On this request, we need the callback url for freshbooks to redirect after the authorization was made. Once we get the token, we will submit it to authorization url for users to authorize our application.
$key = '<your oauth key here>';
$secret = '<your oauth secret here>';
// call request token here and pass the App key and App secret
request_token($key, $secret);
function request_token($key='', $secret='') {
$timestamp = time();
$nonce = md5(time());
$key = $this->data['key'];
$secret = $this->data['secret'];
$sig = $secret."%26";
$method = "PLAINTEXT";
$callback = "http://".$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']; // put your callback url
$url = "https://$key.freshbooks.com/oauth/oauth_request.php";
$param = "oauth_consumer_key=$key".
"&oauth_signature_method=$method".
"&oauth_signature=$sig".
"&oauth_timestamp=$timestamp".
"&oauth_nonce=$nonce".
"&oauth_version=1.0".
"&oauth_callback=$callback";
$output = $this->post_request($url, $param);
// parse the output
parse_str($output, $token);
// save to session
$_SESSION['oauth_token'] = $token['oauth_token'];
$_SESSION['token_secret'] = $token['oauth_token_secret'];
// redirect to authorize url
authorize($key);
}
After getting a token from request token url, we can redirect the users to authorize url with the oauth token we get from request token.
function authorize($key='') {
$oauth_token = $_SESSION['oauth_token'];
$url = "https://$key.freshbooks.com/oauth/oauth_authorize.php";
$param = "oauth_token=$oauth_token";
header("Location: $url?$param");
}
Once the user allow the application to access the users information, Freshbooks will redirect the users to the callback url we put in our request token function. The callback url should be our access token function to get the access token that we can use moving forward.
$key = '<your oauth key here>';
$secret = '<your oauth secret here>';
// call access token request passing the App key and App secret parameters
access_token($key, $secret);
function access_token($key='', $secret='') {
$oauth_token = ($_GET['oauth_token']) ? $_GET['oauth_token'] : $_SESSION['oauth_token'];
$oauth_verifier = $_GET['oauth_verifier'];
$token_secret = $_SESSION['token_secret'];
$timestamp = time();
$nonce = md5(time());
$sig = $secret."%26".$token_secret;
$method = "PLAINTEXT";
$url = "https://$key.freshbooks.com/oauth/oauth_access.php";
$param = "oauth_consumer_key=$key".
"&oauth_token=$oauth_token".
"&oauth_signature_method=$method".
"&oauth_signature=$sig".
"&oauth_timestamp=$timestamp".
"&oauth_nonce=$nonce".
"&oauth_version=1.0".
"&oauth_verifier=$oauth_verifier";
$output = post_request($url, $param);
// parse the output
parse_str($output, $token);
// save to session
$_SESSION['oauth_token'] = $token['oauth_token'];
$_SESSION['token_secret'] = $token['oauth_token_secret'];
}
We need to save the oauth token and oauth token secret for api call. Please watch out for my next post, I'll be posting on how to do the API call using OAuth method. Check out below script for the full implementation of the freshbooks authentication.
<?php
session_start();
$key = '<your oauth key here>';
$secret = '<your oauth secret here>';
// from callback
$oauth_token = $_GET['oauth_token'];
if ($oauth_token) {
access_token($key, $secret);
} else {
request_token($key, $secret);
}
function request_token($key='', $secret='') {
$timestamp = time();
$nonce = md5(time());
$key = $this->data['key'];
$secret = $this->data['secret'];
$sig = $secret."%26";
$method = "PLAINTEXT";
$callback = "http://".$_SERVER['HTTP_HOST'].$_SERVER['REQUEST_URI']; // put your callback url
$url = "https://$key.freshbooks.com/oauth/oauth_request.php";
$param = "oauth_consumer_key=$key".
"&oauth_signature_method=$method".
"&oauth_signature=$sig".
"&oauth_timestamp=$timestamp".
"&oauth_nonce=$nonce".
"&oauth_version=1.0".
"&oauth_callback=$callback";
$output = $this->post_request($url, $param);
// parse the output
parse_str($output, $token);
// save to session
$_SESSION['oauth_token'] = $token['oauth_token'];
$_SESSION['token_secret'] = $token['oauth_token_secret'];
authorize($key);
}
function authorize($key='') {
$oauth_token = $_SESSION['oauth_token'];
$url = "https://$key.freshbooks.com/oauth/oauth_authorize.php";
$param = "oauth_token=$oauth_token";
header("Location: $url?$param");
}
function access_token($key='', $secret='') {
$oauth_token = ($_GET['oauth_token']) ? $_GET['oauth_token'] : $_SESSION['oauth_token'];
$oauth_verifier = $_GET['oauth_verifier'];
$token_secret = $_SESSION['token_secret'];
$timestamp = time();
$nonce = md5(time());
$sig = $secret."%26".$token_secret;
$method = "PLAINTEXT";
$url = "https://$key.freshbooks.com/oauth/oauth_access.php";
$param = "oauth_consumer_key=$key".
"&oauth_token=$oauth_token".
"&oauth_signature_method=$method".
"&oauth_signature=$sig".
"&oauth_timestamp=$timestamp".
"&oauth_nonce=$nonce".
"&oauth_version=1.0".
"&oauth_verifier=$oauth_verifier";
$output = post_request($url, $param);
// parse the output
parse_str($output, $token);
// save to session
$_SESSION['oauth_token'] = $token['oauth_token'];
$_SESSION['token_secret'] = $token['oauth_token_secret'];
var_dump($_SESSION);
}
?>