|
Re: OpenID, YADIS and Directed Identity: msg#00097web.openid.general
... in my Not necessarily. The identity server can have a cookie, shared only with itself, that identifies who you are. So the sequence would be GET relying-party -> HTML form POST relying party identity=whatever.com -> Redirect to whatever.com GET whatever.com cookie=myid -> Redirect to whatever.com/myid GET whatever.com/myid -> Redirect to relying party with signed URL (if active session, otherwise ask for password first) P.S. No hunting party ;-) as long as everybody understands that this is about something other than YADIS 1.0. Johannes Ernst NetMesh Inc. http://netmesh.info/jernst |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: OpenID, YADIS and Directed Identity: 00097, Michael Graves |
|---|---|
| Next by Date: | Re: OpenID, YADIS and Directed Identity: 00097, Michael Graves |
| Previous by Thread: | Re: OpenID, YADIS and Directed Identityi: 00097, Michael Graves |
| Next by Thread: | Re: OpenID, YADIS and Directed Identity: 00097, Michael Graves |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |