(My point is that this is cool, but it really isn't enough)
For instance, I'm using facebook auth on http://lanmarks.com -- I wanted to be able to pull my users' facebook friends so that they could filter the data on my site to only their set of friends (this is one of the appealing parts of facebook auth, imho).
I spent a bit of time looking around the API docs searching for the option for "allow me to see their friends", figuring that I would have to ask my existing users to re-auth against facebook with the new permissions.
Nope. I get that by default, and I can pull a list of your friends silently in the background.
This is with the most basic authentication mechanism that facebook offers.
That's...scary to me. As I was building this out, I asked a friend of mine on gchat to go to the site and auth against facebook to check that the functionality was working.
It was... I was watching my DB, and without facebook even telling her, it grabbed a JSON of all of her friends.
Creeeepy
_I_ tell people this on the site (this will get your name and people in your network), but I wish that facebook did too. At least I wish they made it more obvious.
And you know what? Honestly, facebook, you're totally dropping the ball on oauth here. Where in your documentation does it explain how to exchange an expired token for a new one?
Most devs end up requesting a permission called "offline_access", which facebook explains as "The application can access my data at any time"
This, along with "stream_access" (which most apps also ask for) literally means that the developer can post to facebook, as you, without you knowing it, whenever they want and with whatever they want.
That's bad, facebook. That's bad to the point where I actually disabled facebook integration on http://thingist.com/. The idea that my application could just post a status as any of my users, and it could do so without any interaction from them...was just too much.
C'mon facebook, stop making it so hard for me to defend you all the time.
(By the way, you don't really need a plugin to do this. Have a look right here: http://developers.facebook.com/docs/reference/api/permission...
then look at the URL in the window that you end up in at facebook.com -- the one prompting you for permissions. Just edit the URL to reflect the permissions that you want to give the app.)