If you mean: I have an authentication service, Auth.com, and I would like the users to be able to enter their user name and password on AnotherSite.com, how do I stop javascript on AnotherSite.com hijacking their submission to Auth.com?
Then the short answer is, you can't. That is why all services redirect you to their own login page, where they control the HTML (and can audit to be sure that no one has injected code into their site).
What Facebook does is usually in an iFrame, which accesses the user information relatively securely. Any interaction more complex than a "like" is generally redirected via facebook.com (e.g. any permission grants). iFrame's used to be riddled with flaws, but I believe they are considered fairly safe these days.
Go educate yourself on the protection of XSS and CSRF/XSRF, and you'll be able to answer all of your own questions.