[OpenID] Problems with OpenID and TAG httpRange-14

Brendan Taylor whateley at gmail.com
Wed Mar 5 02:56:55 UTC 2008


On Tue, Mar 04, 2008 at 09:09:12PM +0000, Noah Slater wrote:
> On Tue, Mar 04, 2008 at 04:04:15PM -0500, John Kemp wrote:
> > Thanks for explaining your issue so well - I'm sorry if I seem dense,
> > but I'm just trying to understand the practical effect of this on the
> > OpenID protocol...
> 
> Thank you for taking the time to step through it with me, I appreciate it's an
> edge case, but stil it's worthy of some attention IMHO.
> 
> I will wait for some other people to chip in with opionions on this list.

I've been thinking about this too. I think it's quite clear that the
correct* thing for an RP to do when receiving a 303 response is use
the just-requested URL as the claimed identifier and follow the redirect
to find the OP.

* according to httpRange-14, and in order to work properly with SemWeb
  stuff
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
URL: <http://lists.openid.net/pipermail/openid-general/attachments/20080304/21e09fd1/attachment-0002.pgp>


More information about the general mailing list