[PROPOSAL] request nonce and name

Josh Hoyt josh at janrain.com
Fri Oct 13 00:07:36 UTC 2006


On 10/12/06, Marius Scurtescu <marius at sxip.com> wrote:
> If passing through all unrecognized parameters can cause problems
> then there could be a special namespace for this purpose. For
> example, all parameters with names starting with openid.pass. should
> be ignored by the IdP and passed back to the RP.

Yahoo Browser-based authentication [1] has a single parameter called
"appdata" (that you can find in [2]) that is used for this purpose.
This seems general enough to me.

Josh

1. http://developer.yahoo.com/auth/
2. http://developer.yahoo.com/auth/user.html



More information about the specs mailing list