All - let me attempt to clarify the problem / question. I’m not sure it’s been stated.
Suppose that web application X wants their users to “Sign in with Twitter.” They want to send their users to a single Twitter URL that:
(1) sends them right back to the website if they’ve already granted all permissions
(2) asks that they “upgrade” to DM if they previously only had R&W access
(3) asks them to grant R&W&DM if the user has never seen them before.
This is, I imagine, the most popular use-case scenario that any app could possibly face. What is the URL for this to work? Is it authorize, authenticate? Do we pass in force_login or not? Does this work with @abraham’s PHP library?