FB Connect security issue

Hi all,

           Was wondering if anyone else has been experiencing any security issues with FB connect.

Had a couple of people sending messages that they are getting logged in as another member after signing up with FB with full access to that members account on our site.

 

Most recent message from user:

 

"Looks like a bug that when you login and limit the access of FB connect to your profile and no email it can't recognise the user and logs you in as a random user. On iPad mini using the FB app and in its built in browser Bug is still active, Sorry"

 

TIA

Ed

It ain't easy being this stupid all of the time
Quote · 7 Nov 2015

yes happened with me. One of my friend joined with facebook connect ..in data base his email section was empty, so when ever i used my facebook connect account i was going to his profile and all my friends were receiving auto friendship msgs by his name. so i had to delete him. it was creating  error in the database. so far no other complain. Only happened with me so saved me from embarrassment. Go to admin panel>member> and select geeky view. check if any member have empty email section. you might need to delete them n ask them to join again.

Umar Haroon
Quote · 7 Nov 2015

Thanks Moonsoon2u

The issue arose when someone tried to sign up through FB connect and denied access to his email so FB connect in its infinite wisdom just logged him in as another user with access to all their info

 

So i either have to remove the email permission which may cause untold other issues or he won't be able to join through FB connect.

Surely there must be a way which would deny him membership through FB connect if he declines the permission to email?

It ain't easy being this stupid all of the time
Quote · 7 Nov 2015
 
 
Below is the legacy version of the Boonex site, maintained for Dolphin.Pro 7.x support.
The new Dolphin solution is powered by UNA Community Management System.