28 ms·
it is a questionaire about yourself and the app needs the data to create the questions. it is plain javascript with no backend attached to it. the data only get
by maxkiener 12y ago
it is a questionaire about yourself and the app needs the data to create the questions. it is plain javascript with no backend attached to it. the data only gets sent back and forth between your browser and fb. none of your data ever gets stored on "my" server. hope this helps.
- MasterScrat 12y ago> the data only gets sent back and forth between your browser and fb That's... actually a very interesting way to put it. There should be a way to make a Facebook application that could guarantee it can't leak information to any other server.
- CSDude 12y agoIt can't be done. I could get the data from FB with javascript, and If I'm using it, I can sent it to my server with another request, so there is no way to block that.
- MasterScrat 12y agoI know, that's why I'm saying there should be a way. One solution would be for Facebook to host the app, and to run its content in a sandbox (using something like Google's Caja?). Another approach would be a system permission at the browser level, where a page could explicitly request to restrict what it is allowed to do. Then you could have an approach where the app asks Facebook for this and that permissions, but accepts to be sandboxed to only have access to Facebook's domains. The request goes to FB as it does now. FB calls the return URL, but it opens it in tab with specially sandboxed permissions. Everyone wins: the app makes it clear there's no information leak possible and the user is feeling safer. I'm not saying any of this is trivial to implement. But it would make sense from a user perspective.