[OpenID] Requiring Pseudonymous Identifier

SitG Admin sysadmin at shadowsinthegarden.com
Wed May 13 16:17:16 UTC 2009


>>  Then, am I out of spec for offering a dedicated OP where the 
>>*users* do NOT control the identifier; they merely use 
>>'shadowsinthegarden.com/everyone' to log in with the ACL permitted 
>>to everyone?
>>
>
>You are not out of spec, but that violates assumptions that are made 
>by many relying parties.

I probably should have made that more clear: by "dedicated", I meant 
that the OP works exclusively with my RP; it does NOT provide login 
to other sites.

So, assumptions made by other RP's should not be intruded upon by 
this OP; it will never send an assertion to them.

-Shade



More information about the general mailing list