IRC Log for #openid on 2007-09-03
Timestamps are in UTC.
- [12:35:01] <melvster>
- [12:37:10] <openid_pibb>
<Blueberry> Hi melvster
- [15:21:05] * markjones ( has joined #openid
- [17:59:56] * martin-t ( has joined #openid
- [18:01:25] * martin-t ( has joined #openid
- [18:34:19] * jettero (n=lulz@pdpc/supporter/active/jettero) has joined #openid
- [18:34:40] <jettero>
I just spent the last 3 hours debugging something that would have been solved instantly by right clicking noscript and selecting unsafe reload
- [18:34:52] <jettero>
xss sanitizing my butt. all it did was ruin the sig
- [18:45:37] * SunWuKung ( has joined #openid
- [18:47:50] * martin-t ( has joined #openid
- [18:50:24] <keturn>
jettero: owch. I've been there myself, I'm afraid. I put a message in the noscript forum about it (which appears to be a terrible single never-ending mozillazine thread), but got no response.
- [20:24:59] <jettero>
keturn that's about what I'd expect. It's an obscure problem at best...
- [20:25:32] <jettero>
I discovered that I could detect when it happened because my openid lib returns a nonsense error. The code is invalid sig, but the verbose message is blank, so I replace that with "if you have noscript, do an unsafe reload" done.
- [20:26:07] <jettero>
also, you can put "openid.mode" in the list of allowed regular expressions and you're all set.
- [20:26:09] <keturn>
hmm. I don't suppose you can detect noscript from the server-side?
- [20:37:53] <jettero>
- [20:37:56] <jettero>
that's what I meant
- [20:38:19] <jettero>
the failure is distinct because most of the arguments are there, but they're adulturated by the "sanitizing" noscript does
- [20:38:26] <jettero>
so the signature fails...
- [20:39:32] <jettero>
happily, it only seems to fail during a delayed checkid_setup where the user POSTs a password and from there is redirected back to your site
- [20:39:45] <jettero>
that literally is an xss, so noscript is correct...
- [20:39:52] <jettero>
if a tad misguided maybe
- [20:41:21] <jettero>
- [21:02:43] <openid_pibb>
<nicerobot> Appears to be a problem with using MySQLStore.php. FileStore.php works fine.
- [21:03:46] <openid_pibb>
<> hello, where may i check all the existing field names for use with Auth_OpenID_SRegRequest::build ?
- [21:09:36] <slitzferrari>
hello, i need a list of all available fields to use with Auth_OpenID_SRegRequest::build
- [21:09:44] <slitzferrari>
where can i see it?
- [21:11:21] <keturn>
if that's just a matter of the defined sreg fields, you can look in the spec at
- [21:12:41] <slitzferrari>
thank you :) that's just what i needed !
- [21:13:42] <slitzferrari>
if i need anything that's not in that list i need to ask in my own site right?
- [21:13:49] <slitzferrari>
like an address
- [21:16:20] <openid_pibb>
<Matt Nordhoff> nicerobot: It seems your multi-line message didn't get through to the IRC channel.
- [21:16:45] <keturn>
slitzferrari: yep
- [21:18:46] <openid_pibb>
<nicerobot> Strange. No worries. I've discovered the problem anyway. A database connection issue. There was no error handling when a connection fails.
- [21:19:59] <openid_pibb>
<Matt Nordhoff> Oh, okay.
- [21:26:14] <openid_pibb>
<Matt Nordhoff> test<br><br>test<br>
- [22:47:48] <slitzferrari>
i'm trying to use openid2 client, it works on but it doen's work at and verisign
- [22:47:55] <slitzferrari>
is this normal?
- [22:48:03] <slitzferrari>
i mean, should i use v1 ?
- [23:06:03] <slitzferrari>
err i just found out that if i try the same signon openid with the given example that came with the openid lib it doen't work either
- [23:06:07] <slitzferrari>
any idea?
- [23:55:07] * tommorris ( has joined #openid
