3 ms·
Does this actually work? I mean, wouldn't the application just go ahead and use those privileges anyway, since it was built into the API? I think this just make
by loveat528hz 15y ago
Does this actually work? I mean, wouldn't the application just go ahead and use those privileges anyway, since it was built into the API? I think this just makes you aware of the privileges it intends to use, and doesn't actually affect what the application can and cannot do.
I'd love it if somebody could prove me wrong, though. This would be swell if it worked. :P
- chadrs 15y agoI included a link to the Facebook application settings on the extension's space so you can verify which permissions you've granted and which you haven't. Basically, when you generate a connect button, you list the which permissions you want to ask for and you get redirected to a page that asks for those permissions. My extension just changes the URL of the popup window so Facebook will be asking for different permissions. Before yesterday, I've always just done this manually, but I was surprised to learn that people didn't know this trick. So, last night at 10pm I decided to just sit down and finally write it as an extension.
- latortuga 15y agoPart of the API request sent to Facebook at the time of authorization specifies which permissions you want the user to grant. I have not inspected his code but I think it should be possible to modify those permissions before agreeing to them. The side effect of this is that the webapp you are authorizing may work unexpectedly when it cannot access services/functionality that they originally indicated that they wanted you to agree to. Short answer: your OAuth token includes permission status so yes, this should work.