facebook - Insecure handling of signed_request -
i've noticed several fb applications handle signed_request in insecure way. f.ex load application page-tab, fb posts signed_request app. app redirects me further site passing signed_request variable.
in theory it's atleast less secure, have facebook put out guidelines/rules on how handle signed_requests or applications free whatever want?
f.ex load application page-tab, fb posts signed_request app. app redirects me further site passing signed_request variable.
passing via not harmful per se – long embed no external resources page (because transfered http referer).
but don’t see real reason pass signed_request parameter around – once decoded , verified, put session , have access whenever want.
in theory it's atleast less secure, have facebook put out guidelines/rules on how handle signed_requests or applications free whatever want?
handling token responsibility – , if in way gets stolen , misused spam, fb block app.
Comments
Post a Comment