Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 9147579
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 17, 20262026-06-17T11:01:24+00:00 2026-06-17T11:01:24+00:00

I have the following use case My application on iOS is using the FaceBook

  • 0

I have the following use case

  1. My application on iOS is using the FaceBook iOS SDK to authenticate with FB
  2. The application then make a REST call over https to my server to register the FB account to their service account (the service I am offering)

In step 2 the client is sending the FaceBook UID.

My problem is that the server has no FB integration so has to reply on the client sending the right FaceBook UID.

So the problem is obvious, a hacker can attach someone else FaceBook account to their service account .

What I would like is for the server (Java) to be able to validate that the user who is sending the request owns the Facebook UID in question.

I have been searching online and cannot find anything that I think will work.

I came across a vague post about using the FB signedRequest field, this could be passed to the server to validate the user.

Any idea would be appreciated.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-17T11:01:25+00:00Added an answer on June 17, 2026 at 11:01 am

    Here is a thought:

    Once you authenticate the user in your iOS app, get the access_token, and pass only this in your REST call to your server.

    On the server side, make a request to https://graph.facebook.com/me?access_token=... using the access_token that you transmitted. If the access token is valid, you will get all the the user’s data proving that you have a valid, authenticated user.

    If you wanted to be extra sure, you can also request http://graph.facebook.com/app?access_token=... to be sure that the access token was created by your app.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have the following use case: My application is started with an Ant Script,
I have the following use case for debugging a PHP application: The developer does
I have following use-case: there are several assemblies decorated with ProtoContract classes and I
I have the following use case: There's a class called Template and with that
I have had the Facebook iOS SDK running in an app I've been working
I have the following use case for my Tornado web server: Upon POST requests
I have the following use case: I have a number of standard entities in
I have a Java Applet application. The use case is as follows: The users
My use-case: I already have a working ASP.NET application I would like to implement
In my application, we already have Map<String, List<String>> Now we got another use-case where

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.