4
votes

I'm developing an iOS app which uses Facebook Login. I have the Facebook iOS SDK set up and working, but the back-end developer of my client has concerns about the safety of Facebook's access tokens.

Using using the Facebook SDK, We want to get an authorization code from Facebook, not the access token, and get the access token on the server with App Key and App Secret. Is there any way of doing this?

Note: I am using this method to login (on FBSession):

openActiveSessionWithReadPermissions:allowLoginUI:completionHandler:
1

1 Answers

3
votes

Answering my own question :

This can't be done with the current Facebook iOS SDK, but you can make a graph API call to

https://graph.facebook.com/oauth/client_code?access_token=...&client_id=...&client_secret=...&redirect_uri= ...

to exchange the access token with the code.

But this isn't secure at all, because you would have to ship the app with the App Secret.