3 ms·
Only if the act of logging out explicitly invalidates the token on the server side
by kidsnow 8y ago
Only if the act of logging out explicitly invalidates the token on the server side
- dylan604 8y agoThis is something I would suspect doesn't actually happen. FB wants to track all of the user's browsing habits, so maybe they just make the actual FB UI look logged out? Security-wise, it would seem to be more complicated by their desire to never let a user be logged out, and looks like it's complicated enough it is biting them in the backside. Oops?!
- dasil003 8y agoIt’s not really that complicated, you have auth tokens and you have tracking tokens, and you wouldn’t want to mix them anyway because you also want to be able to correlate multiple accounts logged in from the same browser over time.