Right, let's go back to what you mentioned. What do you consider a solution?
If the simple approach is not enough for you what do you suggest to make this feature possible?
I still think it's not as concerning as you want us to believe otherwise other websites with social features wouldn't do it.
For me, having oauth is overkill in this case but would that address your concerns?