Security is all about risks. Most companies aren’t at the scale of Facebook so the much rely on simple heuristics.
Facebook likely has enough ancillary data to not really even need your password. They’ve seen a bunch of prior usage from a device identical to your current one. Your IP matches known Ip for your session. There’s some cookie on your system that’s associated with you. Perhaps, even Facebook knows the handful of people that ever share WiFi with you.
Essentially, they already know who you are, so they’re willing to take anything that’s close to a known password.