I am asking another question.
If I am operating an OpenID provider, say Auth.com, and CoolStuff.com uses me to authenticate a user, then they can use that session. Great. But now let's say I operate an OAuth provider, and it releases this user's uid, first_name and last_name. What measures does facebook and other OAuth providers take to prevent the uid, first_name, last_name and other data from just being changed by the user in javascript, before being posted to the CoolStuff.com servers, after they have been obtained using Javascript ... such as FB.api('fql.query', ...)