facebook - Insecure handling of signed_request -


i've noticed several fb applications handle signed_request in insecure way. f.ex load application page-tab, fb posts signed_request app. app redirects me further site passing signed_request variable.

in theory it's atleast less secure, have facebook put out guidelines/rules on how handle signed_requests or applications free whatever want?

f.ex load application page-tab, fb posts signed_request app. app redirects me further site passing signed_request variable.

passing via not harmful per se – long embed no external resources page (because transfered http referer).

but don’t see real reason pass signed_request parameter around – once decoded , verified, put session , have access whenever want.

in theory it's atleast less secure, have facebook put out guidelines/rules on how handle signed_requests or applications free whatever want?

handling token responsibility – , if in way gets stolen , misused spam, fb block app.


Comments

Popular posts from this blog

get url and add instance to a model with prefilled foreign key :django admin -

css - Make div keyboard-scrollable in jQuery Mobile? -

android - Keyboard hides my half of edit-text and button below it even in scroll view -