<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: OpenID login and APIs</title>
	<atom:link href="http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis/feed" rel="self" type="application/rss+xml" />
	<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis</link>
	<description>scratched tallies on the prison wall</description>
	<pubDate>Mon, 01 Dec 2008 22:17:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Anonymous</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121629</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Thu, 10 Jul 2008 17:09:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121629</guid>
		<description>What are the differences between OpenID and Shibboleth? http://en.wikipedia.org/wiki/Shibboleth_%28Internet2%29</description>
		<content:encoded><![CDATA[<p>What are the differences between OpenID and Shibboleth? <a href="http://en.wikipedia.org/wiki/Shibboleth_%28Internet2%29" rel="nofollow">http://en.wikipedia.org/wiki/Shibboleth_%28Internet2%29</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lefty</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121620</link>
		<dc:creator>Lefty</dc:creator>
		<pubDate>Thu, 10 Jul 2008 08:42:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121620</guid>
		<description>Comments look fine in FF3, but not on my Diablo-ized N810...</description>
		<content:encoded><![CDATA[<p>Comments look fine in FF3, but not on my Diablo-ized N810&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erwan</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121612</link>
		<dc:creator>Erwan</dc:creator>
		<pubDate>Thu, 10 Jul 2008 01:44:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121612</guid>
		<description>I think that Ma.gnolia.com has already done some research about that. They have an API, they provide OpenID login but you can't use the API with OpenID.

Last time I talked to them about that they explained me they would have to do the trick Ian explained: have the user copy/paste some token. Because that would be an awkward experience, it wasn't super high on their priority list.</description>
		<content:encoded><![CDATA[<p>I think that Ma.gnolia.com has already done some research about that. They have an API, they provide OpenID login but you can&#8217;t use the API with OpenID.</p>
<p>Last time I talked to them about that they explained me they would have to do the trick Ian explained: have the user copy/paste some token. Because that would be an awkward experience, it wasn&#8217;t super high on their priority list.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian McKellar</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121609</link>
		<dc:creator>Ian McKellar</dc:creator>
		<pubDate>Wed, 09 Jul 2008 20:49:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121609</guid>
		<description>I kicked up a minor fuss when OAuth was being developed over open source applications, and desktop applications in general (since it's easy to extract secrets from desktop apps - see: http://ianloic.com/2006/12/23/flickr_authentication_security/). It looks like they made the language more stupid before releasing the spec. FAIL. I need to tell those guys off more often.

So, one fairly simple approach is to make users of the web application retrieve a token from the web site when they've logged in and put that into the desktop program that will be making requests. Make it something that copies &#38; pastes nicely and only expires when you explicitly expire it or change your password.</description>
		<content:encoded><![CDATA[<p>I kicked up a minor fuss when OAuth was being developed over open source applications, and desktop applications in general (since it&#8217;s easy to extract secrets from desktop apps - see: <a href="http://ianloic.com/2006/12/23/flickr_authentication_security/" rel="nofollow">http://ianloic.com/2006/12/23/flickr_authentication_security/</a>). It looks like they made the language more stupid before releasing the spec. FAIL. I need to tell those guys off more often.</p>
<p>So, one fairly simple approach is to make users of the web application retrieve a token from the web site when they&#8217;ve logged in and put that into the desktop program that will be making requests. Make it something that copies &amp; pastes nicely and only expires when you explicitly expire it or change your password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xxx</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121605</link>
		<dc:creator>xxx</dc:creator>
		<pubDate>Wed, 09 Jul 2008 13:25:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121605</guid>
		<description>actually, it doesn't work well on ff 2 either</description>
		<content:encoded><![CDATA[<p>actually, it doesn&#8217;t work well on ff 2 either</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sil</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121604</link>
		<dc:creator>sil</dc:creator>
		<pubDate>Wed, 09 Jul 2008 13:06:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121604</guid>
		<description>James: yeah, I didn't bother too much with IE support. I've now poked it so comment text isn't overlain. Still not too bothered about IE support, though.</description>
		<content:encoded><![CDATA[<p>James: yeah, I didn&#8217;t bother too much with IE support. I&#8217;ve now poked it so comment text isn&#8217;t overlain. Still not too bothered about IE support, though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121603</link>
		<dc:creator>James</dc:creator>
		<pubDate>Wed, 09 Jul 2008 12:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121603</guid>
		<description>I'd love to comment, but christ, your comments are a dog's breakfast, lines a single word long overwriting each other so I can't read what's already been said.</description>
		<content:encoded><![CDATA[<p>I&#8217;d love to comment, but christ, your comments are a dog&#8217;s breakfast, lines a single word long overwriting each other so I can&#8217;t read what&#8217;s already been said.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lefty</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121602</link>
		<dc:creator>lefty</dc:creator>
		<pubDate>Wed, 09 Jul 2008 12:29:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121602</guid>
		<description>is http://openidenabled.com/files/php-openid/docs/2.0.1/OpenID/tutorial_OpenID.pkg.html helpful?</description>
		<content:encoded><![CDATA[<p>is <a href="http://openidenabled.com/files/php-openid/docs/2.0.1/OpenID/tutorial_OpenID.pkg.html" rel="nofollow">http://openidenabled.com/files/php-openid/docs/2.0.1/OpenID/tutorial_OpenID.pkg.html</a> helpful?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: You</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121601</link>
		<dc:creator>You</dc:creator>
		<pubDate>Wed, 09 Jul 2008 12:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121601</guid>
		<description>I think Drupal 6 allows open ID based log ins. (create an account, add an open id to it and then you can use the openid to log in etc etc.</description>
		<content:encoded><![CDATA[<p>I think Drupal 6 allows open ID based log ins. (create an account, add an open id to it and then you can use the openid to log in etc etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: sil</title>
		<link>http://www.kryogenix.org/days/2008/07/09/openid-login-and-apis#comment-121595</link>
		<dc:creator>sil</dc:creator>
		<pubDate>Wed, 09 Jul 2008 09:07:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.kryogenix.org/days/?p=1526#comment-121595</guid>
		<description>Simon: right, OK. Sounds a bit fiddly to set up if all you want is a fairly noddy script rather than a full-on application, but I suppose that's the way in the new world order.</description>
		<content:encoded><![CDATA[<p>Simon: right, OK. Sounds a bit fiddly to set up if all you want is a fairly noddy script rather than a full-on application, but I suppose that&#8217;s the way in the new world order.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
