When a user visits my domain, sessionid is issued by django. When he tries to make Oauth with Facebook, he clicks a button on my site that redirects to Facebook.com. Facebook redirects back to my domain, but at the moment the user session is lost, and Django seems to be issuing a new session variable.
I want the pending session to be saved because I have to link the visitor to my site with my Facebook account, but when the session is deleted, the user registered in the system will log out.
I have a suspicion that this might be a behavior related to django XSS security. How to make user information saved when a user leaves our site to log in to Facebook?
django oauth
Mark
source share