How to pass Facebook Id from client to server securely

后端 未结 4 1877
慢半拍i
慢半拍i 2020-12-19 04:54

I have a Facebook canvas app. I am using the JS SDK to authenticate the user on the browser-side and request various information via FB.api (e.g. name, friends, etc.).

4条回答
  •  悲&欢浪女
    2020-12-19 05:12

    I had exactly the same question recently. It's option 2. Check this post from the Facebook blog.

    To be honest I am not enough of a hacker to know if you could spoof the UID in the cookie, but this seems to be the 'official' way to do it.

    EDIT: to the other question under option 2, yes, I believe you have to access this cookie on your domain.

提交回复
热议问题