Hacker News new | ask | show | jobs
by arice 4841 days ago
Hopefully not too oddly: Facebook was one of the first OAuth 2.0 implementations and the additional benefits of requiring stricter pre-registration was not initially apparent. An unfortunate oversight. For kicks: compare section 5.2.3.5 v00 with v01

Changing the implementation at this point is a daunting task (for both Facebook and our developers) but we do hope to offer it as part of a future migration.

1 comments

Interesting. I didn't know that detail but it explains a lot. Hopefully it won't be too long until you address this!