Yeah, that's an unfortunate circumstance, and we apologize for that. Version 3.2 will have the ability to not allow users to log in if they haven't authenticated their email (if you want it set up that way). We simply hadn't done it till now because most people 'trusted' the Facebook email address that was given by the request permission, but as JFBConnect has grown, we've had a few more requests to allow for more 'private' sites.
One of the goals of JFBConnect was as simple a registration process as possible (no email verification, since emails are trusted, no logging in after registration, etc). However, we realize that every site operates its own way, and will be properly sending out the email authentication emails, and checking the block user status for the user before logging them in in the future. If email verification is disabled, we plan to still automatically log users in immediately after registration.
Sorry, again, for the troubles this may cause you in the short term.