CSRF state token does not match one provided FB PHP SDK 3.1.1 Oauth 2.0
I had a similar issue last week, and tracked it down to the state field being overwritten by multiple calls to getLoginUrl(). Each time you call getLoginUrl(), a new state token is generated in the SDK and stored in the $_SESSION (it’s just a random value), so if you call it twice and the user … Read more