Right. I checked it with JanRain PHP Library and it worked as well. It actually should in other libraries as you point out. <div><br></div><div>=nat <br><br><div class="gmail_quote">On Wed, Oct 29, 2008 at 1:14 AM, Andrew Arnott <span dir="ltr"><<a href="mailto:andrewarnott@gmail.com">andrewarnott@gmail.com</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">I was going through the logs of <a href="http://nerdbank.org/RP/login.aspx" target="_blank">my test RP</a> and was surprised to see what looked like the efforts of someone who didn't understand how OpenID worked. One of the attempts included just using a Yahoo! email address. Guess what?! It worked.<div>
<br>It worked because (at least in .NET), the URL may validly include a user@ portion, as has been discussed on this list recently. It's just quietly dropped. That left "<a href="http://yahoo.com" target="_blank">http://yahoo.com</a>" as the identifier to perform discovery on, which of course worked. To the user, the experience is nearly perfect. They see Yahoo where they must log in, choose an identifier, and then return to the RP. The only weirdness is that although the Claimed Identifier will always be right, if for prettiness' sake the RP were to display the user-supplied-identifier as the user originally typed it in that it might not match who actually logged into Yahoo. </div>
<div><br></div><div>For instance, I can type in <a href="mailto:yourname@yahoo.com" target="_blank">yourname@yahoo.com</a> and completely log in, even though that's not my email address. The claimed ID is mine, and that's what really matters, but it's a little quirky (from the end user's perspective) that I can type in anyone's yahoo email address and it just works. As a new user I may think that I managed to log in as someone else. </div>
<div><br></div><div>Again, I know <span style="font-style:italic">why </span>all this works based on the spec and my implementation of it; I just didn't expect that email discovery would come without at least some work (perhaps to trim off the username@ part). So I was pleasantly surprised.</div>
<div><br>Anyway, something to think about.</div>
<br>_______________________________________________<br>
general mailing list<br>
<a href="mailto:general@openid.net">general@openid.net</a><br>
<a href="http://openid.net/mailman/listinfo/general" target="_blank">http://openid.net/mailman/listinfo/general</a><br>
<br></blockquote></div><br><br clear="all"><br>-- <br>Nat Sakimura (=nat)<br><a href="http://www.sakimura.org/en/">http://www.sakimura.org/en/</a><br>
</div>