[OpenID] Flickr / Yahoo OpenID implementation

Martin Atkins mart at degeneration.co.uk
Tue Jan 13 07:23:24 UTC 2009


Ben Schwarz wrote:
> So without my users specifically saying:
> 
>     Hi, I'm http://flickr.com/photos/benschwarz
> 
>     No really, I'm http://flickr.com/photos/benschwarz
> 
> I cannot confirm that they own the Flickr account that they originally 
> ID'd with.
> While this might be an edge case as far as OpenID goes, I believe it to 
> be highly problematic and somewhat of a barrier for further OpenID 
> implementations.
> 

It sounds like what you're trying to do is prove that the user has a 
particular Flickr username.

Unfortunately I believe that this is exactly what Yahoo! is trying to 
prevent you from doing: they do not wish you to be able to correlate an 
issued OpenID identifier with a Yahoo! mail account nor a Flickr account.

Users can optionally replace the hashed garbage at the end of their URL 
with something more sensible, but of course most users do not, and even 
if they do there's no guarantee that the username in the OpenID 
identifier matches the username on Flickr.




More information about the general mailing list