[PROPOSAL] request nonce and name

Martin Atkins mart at degeneration.co.uk
Thu Oct 12 20:16:47 UTC 2006


Recordon, David wrote:
> 
> We thus believe that any state tracking needed by a stateless RP must be 
> maintained as GET parameters within the return_to argument.  In the case 
> of a stateful RP, it can either do the same thing, or store state via 
> other means such as using a session id within a cookie to reference 
> database data.
> 

Sounds good to me.
+1.




More information about the specs mailing list