Before that, I said that this is impossible, but it is possible.
http://developers.facebook.com/docs/authentication/canvas
Read that is great. You need to decode the Base64 string and verify that the signature is correct, but in addition it gets the user ID among other things (for example, the access token for the .facebook.com chart)
: "" ! , ...
, :)