I need to authorise my Flash game (which runs on Facebook) users against my game server. I’m able to get their data like id, access token, etc, from Facebook on the client (I’m using the Flash Facebook API) but I’m not sure how to authorize them on my game server (e.g. do a login with a database query). One scenario that I have on my mind:
If I could get the same access token from Facebook on both the client (which I already do) and the server (with, for example, a redirect URL, which I tried but does not seems to work), then I could easily compare the two tokens (together with the user IDs) and thus authorize the user.
Any ideas how I could achieve this or something similar?
UPDATE To put it simpler, I want to catch the token that is returned from Facebook on the server-side before it gets to the client (it can be a simple PHP script that parses the URL token parameter). Next, store it in the DB on the server, and when the client queries the server, I can do the comparison.