i I can not understand one thing.
There is a button on my website with the FB.login method from the facebook api JS SDK.
When a user first visits my site, clicks a button - I get some data from my Facebook profile, and then we check on my server in the database whether there is a user with this identifier or not? If not, write a new line. We also create a user profile on my website.
Now the question is, the next time a user visits our site (and presses a button if he is not logged in) - how to define it so that it matches his profile on our website? For example, to show him his profile or that he could change something in him ...
In normal authorization, we compare the password and user login in the database, there is no such possibility. AccessToken is constantly changing. Thought just checks the FB user ID, but then maybe someone can replace their FB ID and enter their profile, right?
What tricks are used in this case?
Denis source
share