<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How not to implement OpenID</title>
	<atom:link href="http://docwhat.org/2008/11/how-not-to-implement-openid/feed/" rel="self" type="application/rss+xml" />
	<link>http://docwhat.org/2008/11/how-not-to-implement-openid/</link>
	<description>Some men are discovered; others are found out</description>
	<lastBuildDate>Fri, 13 Aug 2010 15:37:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: docwhat</title>
		<link>http://docwhat.org/2008/11/how-not-to-implement-openid/comment-page-1/#comment-5984</link>
		<dc:creator>docwhat</dc:creator>
		<pubDate>Sat, 14 Mar 2009 04:16:28 +0000</pubDate>
		<guid isPermaLink="false">http://docwhat.gerf.org/?p=224#comment-5984</guid>
		<description>Hah!  It turns out it &lt;i&gt;was&lt;/i&gt; the OpenID plugin.  We should complain to the author....</description>
		<content:encoded><![CDATA[<p>Hah!  It turns out it <i>was</i> the OpenID plugin.  We should complain to the author&#8230;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert Eccardt</title>
		<link>http://docwhat.org/2008/11/how-not-to-implement-openid/comment-page-1/#comment-5949</link>
		<dc:creator>Robert Eccardt</dc:creator>
		<pubDate>Sun, 25 Jan 2009 23:38:05 +0000</pubDate>
		<guid isPermaLink="false">http://docwhat.gerf.org/?p=224#comment-5949</guid>
		<description>They have a workaround on the SourceForge site:

http://alexandria.wiki.sourceforge.net/OpenID#tocOpenID5

Adding the HTML discovery they mention allows delegation to work for me. But even that is partly broken. It requires me to include the &quot;www&quot; and &quot;index.html&quot; portion of my URL, which I normally leave out. But the whole thing is almost useless anyway, since you can&#039;t use it for their CVS or Subversion.</description>
		<content:encoded><![CDATA[<p>They have a workaround on the SourceForge site:</p>
<p><a href="http://alexandria.wiki.sourceforge.net/OpenID#tocOpenID5"  class="extlink">http://alexandria.wiki.sourcef.....tocOpenID5</a></p>
<p>Adding the HTML discovery they mention allows delegation to work for me. But even that is partly broken. It requires me to include the &#8220;www&#8221; and &#8220;index.html&#8221; portion of my URL, which I normally leave out. But the whole thing is almost useless anyway, since you can&#8217;t use it for their CVS or Subversion.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: docwhat</title>
		<link>http://docwhat.org/2008/11/how-not-to-implement-openid/comment-page-1/#comment-5931</link>
		<dc:creator>docwhat</dc:creator>
		<pubDate>Wed, 26 Nov 2008 02:43:24 +0000</pubDate>
		<guid isPermaLink="false">http://docwhat.gerf.org/?p=224#comment-5931</guid>
		<description>@Will Norris

OpenID should be fixed.  That was, as you point out, my bad.

I also found that Bad Behavior is messing with the ?openid_server=1 requests (they have a signature similar to cross site scripting attacks); so I disabled Bad Behavior for the moment.

However, SourceForge still isn&#039;t able to log in.  It says &quot;Could not verify your OpenID. Please try again.&quot;  (after I&#039;ve added it to my trusted sites, so it got that far)

The HTTP log only shows this:
&lt;pre&gt;
&quot;GET /?openid_server=1&amp;openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&amp;openid.mode=checkid_setup&amp;openid.identity=http%3A%2F%2Fdocwhat.gerf.org%2Fauthor%2Fdocwhat%2F&amp;openid.claimed_id=http%3A%2F%2Fdocwhat.gerf.org%2F&amp;openid.assoc_handle=%7BHMAC-SHA256%7D%7B492c5dbe%7D%7BFUTq4w%3D%3D%7D&amp;openid.return_to=https%3A%2F%2Fsourceforge.net%2Faccount%2Fopenid_verify.php&amp;openid.realm=https%3A%2F%2Fsourceforge.net&amp;openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&amp;openid.sreg.optional=nickname%2Cemail%2Cfullname%2Ccountry%2Clanguage%2Ctimezone&amp;openid.sreg.policy_url=http%3A%2F%2Fsourceforge.net%2Ftos%2Fprivacy.php HTTP/1.0&quot; 302 - &quot;-&quot;
&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p>@Will Norris</p>
<p>OpenID should be fixed.  That was, as you point out, my bad.</p>
<p>I also found that Bad Behavior is messing with the ?openid_server=1 requests (they have a signature similar to cross site scripting attacks); so I disabled Bad Behavior for the moment.</p>
<p>However, SourceForge still isn&#8217;t able to log in.  It says &#8220;Could not verify your OpenID. Please try again.&#8221;  (after I&#8217;ve added it to my trusted sites, so it got that far)</p>
<p>The HTTP log only shows this:</p>
<pre>
"GET /?openid_server=1&#038;openid.ns=http%3A%2F%2Fspecs.openid.net%2Fauth%2F2.0&#038;openid.mode=checkid_setup&#038;openid.identity=http%3A%2F%2Fdocwhat.gerf.org%2Fauthor%2Fdocwhat%2F&#038;openid.claimed_id=http%3A%2F%2Fdocwhat.gerf.org%2F&#038;openid.assoc_handle=%7BHMAC-SHA256%7D%7B492c5dbe%7D%7BFUTq4w%3D%3D%7D&#038;openid.return_to=https%3A%2F%2Fsourceforge.net%2Faccount%2Fopenid_verify.php&#038;openid.realm=https%3A%2F%2Fsourceforge.net&#038;openid.ns.sreg=http%3A%2F%2Fopenid.net%2Fextensions%2Fsreg%2F1.1&#038;openid.sreg.optional=nickname%2Cemail%2Cfullname%2Ccountry%2Clanguage%2Ctimezone&#038;openid.sreg.policy_url=http%3A%2F%2Fsourceforge.net%2Ftos%2Fprivacy.php HTTP/1.0" 302 - "-"
</pre>
]]></content:encoded>
	</item>
	<item>
		<title>By: Will Norris</title>
		<link>http://docwhat.org/2008/11/how-not-to-implement-openid/comment-page-1/#comment-5930</link>
		<dc:creator>Will Norris</dc:creator>
		<pubDate>Wed, 26 Nov 2008 00:11:34 +0000</pubDate>
		<guid isPermaLink="false">http://docwhat.gerf.org/?p=224#comment-5930</guid>
		<description>I have no problems logging into SF, and of course I&#039;m using the WordPress OpenID plugin. :)  I do however have trouble commenting with an OpenID here.  Looks like you moved your wp-comments-post.php file, right?  If so, you need to set OPENID_COMMENTS_POST_PAGE in wp-config.php.  See http://wiki.diso-project.org/WordPress-OpenID#HiddenOptions</description>
		<content:encoded><![CDATA[<p>I have no problems logging into SF, and of course I&#8217;m using the WordPress OpenID plugin. <img src='http://docwhat.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   I do however have trouble commenting with an OpenID here.  Looks like you moved your wp-comments-post.php file, right?  If so, you need to set OPENID_COMMENTS_POST_PAGE in wp-config.php.  See <a href="http://wiki.diso-project.org/WordPress-OpenID#HiddenOptions"  class="extlink">http://wiki.diso-project.org/W.....denOptions</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
