key - What could someone do if they got hold of my Facebook App Id & Secret? -


even if accidentally published fb app id , secret key, how harm app if have no access app dashboard?

first of if did this, should never ever do, should consider changing app secret without further delay.

secondly, question asks, starters can lot of damage people associated application starting you.

  • though won't have user access token account can know permissions have provided application, , if have provided publish_stream permission, many people post app secret on stack overflow do, can post things on wall on behalf. consider major serious issue.

  • they can create migrations

  • create demographic restrictions on app

  • set properties app described in application documentation

  • ban users application

  • and many other things requires app access token described in application's documentation

  • moreover if app behavior under scrutiny then, maybe directly affect facebook account created application directly in many cases you.

so please safeguard app secret build apps users can trust.


Comments

Popular posts from this blog

c# - DetailsView in ASP.Net - How to add another column on the side/add a control in each row? -

javascript - firefox memory leak -

Trying to import CSV file to a SQL Server database using asp.net and c# - can't find what I'm missing -