|
|
|
|
|
by EGreg
5640 days ago
|
|
That's it? That sucks. I don't have to change the token. I just have to change the data given by facebook (including the uid) before the website's dumb javascript uses it in a post back to the server. Since it's not signed by Facebook, how can the website's server trust the uid? Never trust your user input. |
|