[Openid-specs-ab] Spec call notes 24-May-12
ejay at mgi1.com
Fri May 25 00:44:23 UTC 2012
Spec call notes 24-May-12
John Bradley (joined later)
Pam Dingle (joined later)
- Open Issues
#593: Standard: redirect_uri registration & matching
There is still no clear consensus on how to handle the matching of
the redirect_uri value.
This issue is deferred pending more feedback.
#595: Discovery 2 - No means of discovery without web server for domain
Current discovery mechanism relies on a web server at the domain to
host a .well-known file.
Virtual domains or email only providers do not have a web server at
Possible solutions :
1) Use DNS to lookup MX record
2) Require a web server at the domain
The above solutions may be too optimistic
Pam suggested solution # 3 which is performing a GET on the domain
first and if that fails then perform a GET
on the result obtained from a discovery of the domain.
Solution 3 seems most plausible to the members present.
Since WebFinger is still a questionable work item for the OAuth-Apps
group, it is suggested a new spec called
called Simple Web Finger (or something similar) be written and which
profiles a version of WebFingers.
This issue is assigned to John in care of Pam.
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the Openid-specs-ab