1.0.8 • Published 2 years ago
@mich4l/passport-facebook v1.0.8
Untested and not ready to use module - in early stage of development!
Facebook strategy for Passport.js
Easy to use Facebook strategy. Made with backend APIs in mind.
Options
appSecret
(optional) - if provided, strategy will send request withappsecret_proof
parameter. Enable Require App Secret in Advanced Settings if you want to secure your Graph API calls (more info: https://developers.facebook.com/docs/graph-api/securing-requests%20/).
apiVersion
(default:v14.0
) - you can provide specific Graph API version. Strategy is tested by default onv14.0
.tokenFromRequest
(optional) - strategy will use provided function to extract access token from request.
function getAccessToken(req: Request) {
return req.query.accessToken;
}
Important things
- Use HTTPS
- Secure Graph API calls with
appsecret_proof
(https://developers.facebook.com/docs/graph-api/securing-requests%20/) - Never include your secrets directly in your code base - use environment variables instead.
Read: https://developers.facebook.com/docs/facebook-login/security/#checklist