4 ms·
This sounds like major overkill. If the only problem is the data in the iframe url, couldn't they POST the data into the iframe? Create the iframe with some J
by GICodeWarrior 16y ago
This sounds like major overkill. If the only problem is the data in the iframe url, couldn't they POST the data into the iframe?
Create the iframe with some JS that POSTs a form containing the data to the canvas app. The resulting iframe url is the same but without any query parameters.
- SriniK 16y agoYup. Also it's not solving the problem of app developers sharing the UID's intentionally. After the decryption at app's server side, they can share uid as usual. I am not sure if fb has rules for not pushing uid's with 3rd party services - other than that, I don't see how this solution avoids the problem.
- biznickman 16y agoExactly ... this encryption is absolutely useless for intentional sharing. Facebook does have rules against sharing ANY data with third parties, however people are clearly violating that. Update ... I just blogged about it here: http://www.allfacebook.com/is-facebooks-proposed-user-id-solution-sufficient-2010-10 http://www.allfacebook.com/is-facebooks-proposed-user-id-sol...
- finiteloop 16y agoNavigation happens within Canvas iframes, and POSTs make the browser back button more than a little screwy. We definitely considered this.