Steps to reproduce

Imagine:
Alice has a Facebook account, no account yet on your Drupal site
Bob has a Drupal account on your website, and no Facebook account

You need a test Facebook account for Alice, that has never logged in your Drupal site yet. Alternatively, to simulate new user, take your own Facebook account, and delete your site's app in Facebook App Settings, or edit them and remove permission for e-mail.

  1. Log out from both Drupal and Facebook
  2. Use Simple FB Connect to sign up, with Alice account
  3. Deny permission for e-mail during the OAuth flow
  4. Error message is displayed about missing e-mail permission
  5. Login with Bob account

Actual

In his $_SESSION variable, Bob has the Facebook token from Alice, in $_SESSION['simple_fb_connect']['user_token']. This token necessarily has e-mail permission denied (because of error displayed in 4.), but may have any count of other scopes granted, depending on what scopes were requested.

Now, any code that checks presence of this session data and uses it will make Bob act as Alice on Facebook.

Expected

When Bob logs in, he has no simple_fb_connect session data.

Solution

In case of error during the Facebook login flow, simple_fb_connect must delete the session data.

Other possible way: implement hook_user_login() and unset there session data from Simple FB Connect when the login did not happen through Simple FB Connect.

Comments

francoisb created an issue. See original summary.

francoisb’s picture

Here's the fix. It deletes Facebook token from PHP session data for the Drupal anonymous user, when the Facebook login fails.

To verify, please follow the "Steps to reproduce" in issue summary, with and without this patch. At the end, inspect the $_SESSION in any Drupal page with

dpm($_SESSION);

if you have devel module enabled, otherwise with

drupal_set_message(print_r($_SESSION, TRUE));

francoisb’s picture

Status: Active » Needs review
francoisb’s picture

Another possible way to fix this issue: implement hook_user_login() and unset there session data from Simple FB Connect when the login did not happen through Simple FB Connect. What do you think?

francoisb’s picture

Issue summary: View changes

  • masipila committed ffae415 on 7.x-2.x authored by francoisb
    Issue #2829558 by francoisb: Facebook token passed from one user to the...
masipila’s picture

Committed to 7.x-2.x-dev with two changes to the proposed patch:

  • Session data was not removed in a scenario where new Drupal user account was created as blocked (pending admin review)
  • Other session variables than FB access token need to be removed as well because the user was not logged in

Thank you for your work with this issue!

Cheers,
Markus

masipila’s picture

Status: Needs review » Fixed
masipila’s picture

Status: Fixed » Closed (fixed)