Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • Home
  • SEARCH
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6363833
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 25, 20262026-05-25T00:05:13+00:00 2026-05-25T00:05:13+00:00

I am developing a web app in ASP.net that allows users to log in

  • 0

I am developing a web app in ASP.net that allows users to log in using Facebook connect and use the services (like posting a picture or voting for a picture).

To keep the record of user connected via Facebook connect, the user is automatically registered by inserting the unique userid (something like 632343 provided by Facebook) in the database. And the other activities (like posting a picture or voting for a picture) are recorded against user’s unique userid.

When user logs in, his/her private page is loaded by fetching the entries from the database where userId = [user id of the current Facebook connected user]

I was using Facebook JavaScript SDK for this scenario until I discovered that there is a security fail in what I am doing. I am actually getting the userId of the current Facebook connected user and then sending a request to a partial page loadprofile.aspx?user=” to load the private profile page. Anyone who knows the Facebook id of any user can hack the page with tools like ‘Firebug for FireFox’ or by simply sending a get request to loadprofile.aspx?user=[user id] and can fetch the private content of that user.

The only solution I can find is to use the graph API and authenticate the user at Server side to get the userId so that the private page is generated internally for the current Facebook connected user.

I wanted to ask you guys if there is still a secure way of doing this using Facebook JavaScript API because I find it easy to use. Please help.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-25T00:05:14+00:00Added an answer on May 25, 2026 at 12:05 am

    make sure you get javascript sdk loaded with OAuth enabled,
    then for subsequent request, the request should include a code param.
    check it against the validated code

    but frankly speaking, as a better securtiy measure, server side processing is preferred

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I am developing a MySQL Web App using ASP.net and I have heard that
I am developing an ASP.Net web app that needs to run in a Kiosk/Touch
I'm developing an web app using asp.net mvc. I have a List in Cache
I'm developing one web app and for that i need to use UNICODE connect
I've been developing an asp.net web app using VS studio. I'm using SQL Server
I'm currently developing a moderately large sized web app with ASP.NET 2.0 that uses
I am developing a forms app (not web) for Windows Mobile, using .NET CF
I am developing an ASP.NET MVC app and I've been looking into using Data
I'm currently developing a web app on Django/Python, and I consider moving to ASP.NET
I'm developing a web app based on videos that my client would like to

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.