<div>Chris,</div><div><br></div><div>While you bring up a good issue, and it is a problem with the libraries, I would be against building this into the OpenID spec because this is just following the HTML spec, as you point out. There are many more rules in HTML that a good RP discovery library should follow (like ignoring commented out HTML tags, javascript, etc.), and these rules don't belong in the OpenID spec either, IMO.</div>
<div><br></div><div>FWIW, dotnetopenid is one library that can handle both formats you listed. But I do not claim that it has a full browser-quality HTML parser. Just like every library, I imagine, I had to choose how much time to invest in HTML discovery. Unless there's a decent open-source HTML parser available for C#, I don't think any C# openid library will ever have "perfect" html discovery by the HTML spec anyway.</div>
<br clear="all">--<br>Andrew Arnott<br>"I [may] not agree with what you have to say, but I'll defend to the death your right to say it." - Voltaire<br>
<br><br><div class="gmail_quote">On Thu, Jan 8, 2009 at 12:58 AM, Chris Messina <span dir="ltr"><<a href="mailto:chris.messina@gmail.com">chris.messina@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">
I just read over SS 7.3.3 on HTML-Based Discovery [1], and considering my experience today trying to re-delegate my OpenID, I've discovered that this section needs to updated a clarified.<br><br>It turns out that relying parties are not parsing HTML rel values in a standard way. That is, if there is more than one rel value provided for a link, some RPs fail, whereas others work fine.<br>
<br>In other words, this:<br><br> <link rel="<span style="background-color:rgb(255, 255, 51)">openid2.provider openid.server</span>" href="<a href="http://factoryjoe.com/blog/" target="_blank">http://factoryjoe.com/blog/</a>" /><br>
<link rel="<span style="background-color:rgb(255, 255, 51)">openid2.local_id openid.delegate</span>" href="<a href="http://factoryjoe.com/blog/" target="_blank">http://factoryjoe.com/blog/</a>" /><br>
<br>is not the same as this:<br><br> <link rel="<span style="background-color:rgb(255, 255, 51)">openid2.provider</span>" href="<a href="http://factoryjoe.com/blog/?openid_server=1" target="_blank">http://factoryjoe.com/blog/?openid_server=1</a>" /><br>
<link rel="<span style="background-color:rgb(255, 255, 51)">openid2.local_id</span>" href="<a href="http://factoryjoe.com/blog/author/factoryjoe/" target="_blank">http://factoryjoe.com/blog/author/factoryjoe/</a>" /><br>
<link rel="<span style="background-color:rgb(255, 255, 51)">openid.server</span>" href="<a href="http://factoryjoe.com/blog/?openid_server=1" target="_blank">http://factoryjoe.com/blog/?openid_server=1</a>" /><br>
<link rel="<span style="background-color:rgb(255, 255, 51)">openid.delegate</span>" href="<a href="http://factoryjoe.com/blog/author/factoryjoe/" target="_blank">http://factoryjoe.com/blog/author/factoryjoe/</a>" /><br>
<br>It's my understanding that the rel attribute should be able to contain several values.<div><br></div><div>But I can tell you that IntenseDebate, for example, failed when delegation was setup using the former code. It only worked when I broke out the two links into four.</div>
<div><br></div><div>I'm not sure if this is an issue with the libraries or what, but I'd like to know if other people have experienced this problem, and if we can improve the language in the spec to make sure that people understand that they need to look for the presence of an element in a rel value -- not that the *entire* value is one element.<br>
<div><br></div><div>Chris<br><br>[1] <a href="http://openid.net/specs/openid-authentication-2_0.html#html_disco" target="_blank">http://openid.net/specs/openid-authentication-2_0.html#html_disco</a><br><br>-- <br>Chris Messina<br>
Citizen-Participant &<br>
Open Web Advocate-at-Large<br><br><a href="http://factoryjoe.com" target="_blank">factoryjoe.com</a> # <a href="http://diso-project.org" target="_blank">diso-project.org</a><br><a href="http://citizenagency.com" target="_blank">citizenagency.com</a> # <a href="http://vidoop.com" target="_blank">vidoop.com</a><br>
This email is: [ ] bloggable [X] ask first [ ] private<br><br></div></div>
<br>_______________________________________________<br>
general mailing list<br>
<a href="mailto:general@openid.net">general@openid.net</a><br>
<a href="http://openid.net/mailman/listinfo/general" target="_blank">http://openid.net/mailman/listinfo/general</a><br>
<br></blockquote></div><br>