Opened 12 years ago

Closed 7 years ago

#28 closed Bug/Something is broken (fixed)

cyclical openid delegation at MFPL OpenID provider

Reported by: http://users.livejournal.com/_dkg_/ Owned by: Jamie McClelland
Priority: Low Component: Tech
Keywords: openid Cc:
Sensitive: no

Description

[0 dkg@squeak ~]$ wget -q -O- -S https://id.mayfirst.org/dkg
<html>
  <head>
    <link rel="openid.server" href="https://id.mayfirst.org/server/index.php/serve">
    <link rel="openid.delegate" href="https://id.mayfirst.org/dkg">
  </head>
  <body>
    <h3>OpenID Identity Page</h3>

    <p>
    This is the identity page for the user <strong>dkg</strong>.
    </p>
  </body>
</html>
[0 dkg@squeak ~]$

Change History (2)

comment:1 Changed 12 years ago by http://users.livejournal.com/_dkg_/

Priority: MediumLow

gah. meant to add some english describing the above text:

when i pretend that i'm the first-stage of an openid consumer, i'll visit this page, and look for openid.server and openid.delegate info. it seems odd that the page suggests a delegation to the same OpenID url that i supplied.

This might not be an issue, though: it could be an acceptable openid belt-and-suspenders method, i don't know.

comment:2 Changed 7 years ago by Daniel Kahn Gillmor

Resolution: fixed
Status: newclosed

This is no longer the case any more with our use of drupal as our OpenID provider:

0 dkg@pip:/tmp/cdtemp.qFvdr3$ wget -q -O-  https://id.mayfirst.org/dkg | grep -i 'rel="openid'
<link rel="openid2.provider" href="https://id.mayfirst.org/openid/provider" />
<link rel="openid.server" href="https://id.mayfirst.org/openid/provider" />
0 dkg@pip:/tmp/cdtemp.qFvdr3$ 

Please login to add comments to this ticket.

Note: See TracTickets for help on using tickets.