If you hit the callbackURL directly from a local web browser and view the response headers (via Firebug, or the Chrome developer “Network” tab) is the X-Frame-Options header definitely present? (Best to check.) – John Parker Aug 12 ’13 at 13:55
https://stackoverflow.com/questions/18151676/passport-facebook-x-frame-options-to-deny

