sorry for bringing up the issue that has been discussed in the past...
I found this issue tracking from other posts about the same issue.

So it says here the issue is solved, but just wanted to get
clarification on how the issue is solved, and how I should implement
my program.

So I believe, now after user click "deny", they will go to the page
which has link and if user clicks on it he/she goes back to the
callback_url. Is that correct?

Is there any parameter that is attached when callback url is called
that will tell me if user has clicked on "deny"?
If not, do I need to call verify credentials everytime callback url is
accessed just to find out if user has allowed or denied?

Thanks for your help!

