[PROPOSAL] request nonce and name
Martin Atkins
mart at degeneration.co.uk
Thu Oct 12 20:16:47 UTC 2006
Recordon, David wrote:
>
> We thus believe that any state tracking needed by a stateless RP must be
> maintained as GET parameters within the return_to argument. In the case
> of a stateful RP, it can either do the same thing, or store state via
> other means such as using a session id within a cookie to reference
> database data.
>
Sounds good to me.
+1.
More information about the specs
mailing list