key - What could someone do if they got hold of my Facebook App Id & Secret? -
even if accidentally published fb app id , secret key, how harm app if have no access app dashboard?
first of if did this, should never ever do, should consider changing app secret without further delay.
secondly, question asks, starters can lot of damage people associated application starting you.
though won't have user access token account can know permissions have provided application, , if have provided
publish_stream
permission, many people post app secret on stack overflow do, can post things on wall on behalf. consider major serious issue.they can create migrations
create demographic restrictions on app
set properties app described in application documentation
ban users application
and many other things requires app access token described in application's documentation
moreover if app behavior under scrutiny then, maybe directly affect facebook account created application directly in many cases you.
so please safeguard app secret build apps users can trust.
Comments
Post a Comment