Hacker News new | past | comments | ask | show | jobs | submit login

Flaw is my word, but 'cheating' almost implies it. the params are documented here:

https://developers.facebook.com/docs/authentication/permissi...

I thought I would dump my previous links incase you jump into writing an extension. It would be better to contribute to the open source extension than to have yet another project (as we do with removing auth popups on news feed items)

Otherwise nothing against this making news again, the more people that know about it the better




Those extensions are good. I wanted an ext for personal usage that just removes scope at all - no big plans here.

My point is not just 'check this trick' but OAuth2 has no fixed-scope feature at all. You always have to check shit after user did something. This is just lifehack but i am interested in oauth2 spec overall




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: