CB connect: FB registration for already registerd joomla users

9 years 4 months ago #253356 by raidnet
Hi,
Scenario: Joomla 3.0.3 + CB 2.0.3 + FBConnect 6.x
When I try to register via FB connect an user already registered via joomla form, I get the Email already registered error.
Instead using JFBC connect the FB id is automaticaly associated with the existing user in case of already registered email.

Is this features present in FB Connect 6.x?
thx

Please Log in to join the conversation.

9 years 4 months ago - 9 years 4 months ago #253368 by krileon
Automatic email association is a vulnerability. You can edit your Facebook profile and change what email address applications see. Click the button and instantly hijack someones Joomla account. That's not happening; sorry.

What will be implemented is when that error occurs it'll ask if you want to login to link the accounts. This feature is not yet implemented though. It's planned for next release.

For everyones comfort the only information CB Connect trusts from social sites is the users social id. Even in the case of social id it's still verified with an extra API call to be safe. Nothing else is trusted and is treated as such. This is for yours and the users protection. Security has to be number 1 above all else.


Kyle (Krileon)
Community Builder Team Member
Before posting on forums: Read FAQ thoroughly + Read our Documentation + Search the forums
CB links: Documentation - Localization - CB Quickstart - CB Paid Subscriptions - Add-Ons - Forge
--
If you are a Professional, Developer, or CB Paid Subscriptions subscriber and have a support issue please always post in your respective support forums for best results!
--
If I've missed your support post with a delay of 3 days or greater and are a Professional, Developer, or CBSubs subscriber please send me a private message with your thread and will reply when possible!
--
Please note I am available Monday - Friday from 8:00 AM CST to 4:00 PM CST. I am away on weekends (Saturday and Sunday) and if I've missed your post on or before a weekend after business hours please wait for the next following business day (Monday) and will get to your issue as soon as possible, thank you.
--
My role here is to provide guidance and assistance. I cannot provide custom code for each custom requirement. Please do not inquire me about custom development.
The following user(s) said Thank You: nant

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.198 seconds

Facebook Twitter LinkedIn