When running this game https://apps.facebook.com/deadtrigger..., I have to enable facebook connect on all urls since the url the app is running on is changing from one reload to the next. E.g.
integrated-plugin-canvas-463319163784205-2059245125.fbsbx.com
integrated-plugin-canvas-463319163784205-562806970.fbsbx.com
the 2nd number is probably a session-id of some kind.
For this to work, it would be necessary to support wildcard rules on whitelist and exceptions, e.g. in this case integrated-plugin-canvas-463319163784205-*.fbsbx.com
Whitelisting fbsbx.com doesn't quite achieve the same result since I don't know what else is running on the domain (and I do not really want to whitelist everything on the domain)
Loading Profile...



Twitter,
Facebook, or email.
CHAMP
EMPLOYEE
