drudge / passport-facebook-token

Passport strategy for authenticating with Facebook access tokens using the OAuth 2.0 API.
MIT License
390 stars 80 forks source link

Facebook Graph API doesn't require clientId and clientSecret #97

Open edwardanthony opened 4 years ago

edwardanthony commented 4 years ago

I use this library to fetch user profile data after I receive the access_token sent by the iOS app. Using this access_token, I can get the user profile using Facebook Graph API and find the matching user in my database.

Here's my concern though: Fetching data using Facebook Graph API can be accomplished without specifying clientId and clientSecret. Only access token is required.

I'm wondering if I missed something here, maybe I misread the Facebook Graph API documentation, and it does require clientId and clientSecret.

https://developers.facebook.com/docs/graph-api/using-graph-api

Can you give me a short explanation? It would be really helpful.