Hacker News new | ask | show | jobs
by michaeljx 966 days ago
Yup that's the thing, Facebook doesn't do that. The token is the only thing needed, no validation on their half if it matches a client id