How to secure an AJAX call from a facebook canvas application -


Reading this Ajax example,

I'm not sure I got the following line What should be understood about this, how can you "check prices according to each platform device"?

"Note: For a nutshell, we are relying on $$ _POST without checking the full signature, it is unsafe because anyone can easily make user's actions. Be sure to use that the client is supplied with libraries, or check the sig values ​​of each platform space "

You are under Facebook Likeshn is no leakage in the platform, if security, then it is the fault of their platform API. In other words, you are absolutely safe.


Comments