3 ms·
For those who are totally confused as to why an access token is being shared with an end user and why it's transmitted in a URL fragment, I think I figured out
by smarx 14y ago
For those who are totally confused as to why an access token is being shared with an end user and why it's transmitted in a URL fragment, I think I figured out what's going on. Facebook appears to have a flow for logging in client-side in the browser [1]. In that flow, the access token is meant to be delivered to a JavaScript client in the browser, so a URL fragment makes some sense.
I don't know if any of this is covered by the OAuth spec. (I'm only familiar with the so-called "three-legged" OAuth protocol.)
[1] https://developers.facebook.com/docs/howtos/login/client-side-without-js-sdk/ https://developers.facebook.com/docs/howtos/login/client-sid...
- homakov 14y agoresponse_type is also flexible, but spec says explicitely to avoid Implicit flow