John Panzer wrote:

> ...
> I can't find the reference for OpenID Exchange, though -- is there

Sorry for the spastic email.  But I do have a followup regarding the 


> Some servers/frameworks do not allow applications access to the 
> Authorization header

I hope there are no frameworks which block access to Authorization; but 
if there are servers, or environments, which want to lock down 
authentication/authorization, how would the server administrators react 
to a protocol which tunnels around that block?  Or is this a case where 
the default setting blocks access to the header for some reason?


