gpt4 book ai didi

javascript - 将 "app access tokens"与 Facebook Javascript SDK 一起使用吗?

转载 作者:行者123 更新时间:2023-11-28 01:34:08 24 4
gpt4 key购买 nike

我正在为 Facebook 应用程序使用 Javascript SDK,并且 a certain API call我想要制作,需要应用程序访问 token 。然而,the documentation状态:

[…] app access token should never be hard-coded into client-side code, doing so would give everyone who loaded your webpage or decompiled your app full access to your app secret, and therefore the ability to modify your app. This implies that most of the time, you will be using app access tokens only in server to server calls.

和:

Note that because this request uses your app secret, it must never be made in client-side code or in an app binary that could be decompiled. It is important that your app secret is never shared with anyone. Therefore, this API call should only be made using server-side code.

重点甚至不是我的!
那么,如果我只应该在服务器端进行这些调用,那么我该如何使用 JS SDK 进行需要应用程序访问 token 的 API 调用呢?

最佳答案

简短的回答是:你不应该!正如 Adam 所写,如果您公开您的应用程序访问 token ,有人可以从源代码中获取它并用它做任何他想做的事!这是一个安全问题...

关于javascript - 将 "app access tokens"与 Facebook Javascript SDK 一起使用吗?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/21737916/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com