# Unlinking Facebook without Facebook token

**URL:** <https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99>\
**Category:** Local Setup\
**Created:** [July 25, 2019, 6:07pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99 "2019-07-25T18:07:31Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![oscargoldman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/oscargoldman/32/28_2.png) [@oscargoldman](https://forum.heroiclabs.com/u/oscargoldman)\
**Post date:** [July 25, 2019, 6:07pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/1 "2019-07-25T18:07:31Z")

</div>

We trying to manage an edge case with our unity app where someone has already linked a facebook account to their nakama account, but then changes facebook accounts on the mobile app. The facebook unity api uses the oauth token from the mobile app, so there’s a mismatch in facebook ids and tokens. We want to be able to unlink the facebook id from the current namaka profile without using the current access token - is that possible? We can obviously unlink the facebook id from an account in the console without the access token so we’re hoping that can be done with the client too.

---

<div class="post-metadata">

**Author:** ![novabyte](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/novabyte/32/1324_2.png) [@novabyte](https://forum.heroiclabs.com/u/novabyte)\
**Post date:** [July 26, 2019, 10:50am UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/2 "2019-07-26T10:50:30Z")

</div>

@oscargoldman We originally designed the unlink operation with Facebook to require an OAuth token which would ensure that only the authorized user (according to Facebook) could unlink their account but we’ve had a request like yours come up a few times to allow unlink to take just the Facebook ID only. I think it’d be good to open an issue on the tracker and we can look at an enhancement to the API to support it.

In the meantime the only other way I can think you’d be able to workaround the constraints of the API right now are to use custom SQL from an RPC function. Let me know if you want an example to use.

---

<div class="post-metadata">

**Author:** ![oscargoldman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/oscargoldman/32/28_2.png) [@oscargoldman](https://forum.heroiclabs.com/u/oscargoldman)\
**Post date:** [July 26, 2019, 12:53pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/3 "2019-07-26T12:53:42Z")

</div>

Thanks Chris, yeah I think this is more a limitation of the facebook unity SDK. Are you opening that issue or shall I? For SQL, I’ve seen the documentation for pure SQL calls in lua - that should be enough for us to make it happen. Thanks again.

---

<div class="post-metadata">

**Author:** ![oscargoldman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/oscargoldman/32/28_2.png) [@oscargoldman](https://forum.heroiclabs.com/u/oscargoldman)\
**Post date:** [July 26, 2019, 1:47pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/4 "2019-07-26T13:47:43Z")

</div>

What’s the correct way to insert a lua local variable into the sql statement?

---

<div class="post-metadata">

**Author:** ![novabyte](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/novabyte/32/1324_2.png) [@novabyte](https://forum.heroiclabs.com/u/novabyte)\
**Post date:** [July 26, 2019, 1:49pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/5 "2019-07-26T13:49:42Z")

</div>

Please open the issue on GitHub it will be prioritized differently if it’s opened by you rather than as an internal engineering request.

If you’re good with the SQL approach then check the schema [here](https://github.com/heroiclabs/nakama/blob/master/migrate/sql/20180103142001_initial_schema.sql#L33) for how to access the appropriate column and look at [this](https://github.com/heroiclabs/nakama/blob/master/server/console_unlink.go#L143-L170) part of the console server impl for how we handle it. Drop your SQL code into this thread if you want a sanity check on it.

---

<div class="post-metadata">

**Author:** ![oscargoldman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/oscargoldman/32/28_2.png) [@oscargoldman](https://forum.heroiclabs.com/u/oscargoldman)\
**Post date:** [July 26, 2019, 1:55pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/6 "2019-07-26T13:55:40Z")

</div>

oh I see the parameters object.

---

<div class="post-metadata">

**Author:** ![novabyte](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/novabyte/32/1324_2.png) [@novabyte](https://forum.heroiclabs.com/u/novabyte)\
**Post date:** [July 26, 2019, 1:57pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/7 "2019-07-26T13:57:32Z")

</div>

> What’s the correct way to insert a lua local variable into the sql statement?

To insert a SQL-safe variable into the query use placeholder parameters. i.e.

```lua
local sql = [[
UPDATE
    users
SET
    facebook_id = $2, update_time = now()
WHERE
    id = $1 AND facebook_id IS NOT NULL
... etc, see console API link for rest of query
]]
local parameters = { context.user_id, some_facebook_id }
local status, res = pcall(nk.sql_exec, query, parameters)
nk.logger_info(("sql exec status %q res %q"):format(status, res))

```

---

<div class="post-metadata">

**Author:** ![oscargoldman](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/oscargoldman/32/28_2.png) [@oscargoldman](https://forum.heroiclabs.com/u/oscargoldman)\
**Post date:** [July 26, 2019, 2:01pm UTC](https://forum.heroiclabs.com/t/unlinking-facebook-without-facebook-token/99/8 "2019-07-26T14:01:23Z")

</div>

awesome thanks a bunch
