[security-dev] OAuth 2.0 and the Road to XSS: attacking Facebook Platform