IRC Log for #openid on 2007-12-10
Timestamps are in UTC.
- [12:35:52] <eagle^2>
hi, i just tried to install phpopenid 2.0.0 but right away in examples i get this error[ Warning: in_array() []: Wrong datatype for second argument in... ] what can I fix?
- [15:07:19] <darix>
- [15:07:59] <darix>
i wonder, are there any standards to announce "this site supports/requires auth via openid" to non interactive clients?
- [15:13:09] * marclaport1 ( has joined #openid
- [15:13:16] * illustir ( Quit ()
- [15:19:46] <claudio>
darix, "non interactive"?
- [15:22:59] <darix>
claudio: e.g. commandline tools
- [15:25:13] <darix>
or e.g. kde's kio_http
- [15:25:49] <claudio>
ah, oh.. mmmh ok :) Dunno
- [15:26:22] <darix>
atm our service is nicely restful and behind http auth. you can edit files with just specifing "kate http://service/path/to/file" (it will use get and put on save)
- [15:26:35] <darix>
now we need to find a way to tell kio_http do auth and use openid for it
- [15:27:00] <darix>
i hope that example makes it more clear
- [15:28:21] <darix>
that way even our api host could use openid
- [15:29:07] <darix>
claudio: what do you think about the idea?
- [15:51:57] <claudio>
darix, how people actually are authenticating theirselves (to be able, say, to PUT changes on server)?
- [15:52:57] <darix>
claudio: that handling would need to be done in the application.
- [15:53:10] <darix>
showing the local user a popup to put in the openid url
- [15:53:14] <darix>
or read it from their config
- [15:53:56] <claudio>
(Ah, HTTP AUTH, sorry I missed that bit)
- [15:54:08] <darix>
but the problem is to announce the "you need auth and you need to use openid for it" :)
- [15:54:44] <claudio>
yes, the realm string on the HTTP popup will not suffice :)
- [15:56:24] <darix>
ideal would be something like 401 -> WWW-Authenticate: openid
- [15:57:52] <darix>
- [16:00:29] <claudio>
sure, that could be perfect. IIRC Firefox 3 "detects" an openid login in the current page, using the name of the input form elements... I wonder if it could, for example, sniff something like that too
- [16:01:01] <claudio>
so, in that way, one could begin building a "standard"
- [16:01:03] <johill>
darix: question is how you then transfer the credentials etc
- [16:03:32] <darix>
johill: the credentials are only transfered to the provider.
- [16:03:51] <darix>
that is another part of the fun
- [16:04:23] <johill>
yeah, excuse my slack in language. I mean the openid url itself
- [16:05:03] <johill>
and then how do you transfer the credentials to/from the provider? would have to be http auth
- [16:05:19] <johill>
or ssl certificate or something
- [16:05:58] <darix>
johill: hmm the posturl could be part of the WWW-Authenticate: openid header
- [16:06:14] <johill>
ok but then say you log in to the provider
it redirects there to give you a web form
- [16:06:34] <johill>
that's not something you can do non-iteractively
- [16:06:46] <johill>
so you can only work with providers that take http auth or similar
- [16:07:30] <darix>
- [16:07:36] * rorek ( has joined #openid
i will think more about it
- [16:07:51] * illustir ( has joined #openid
- [17:11:42] * rebel_leader ( has joined #openid
- [18:09:27] <PibbRelay>
<samsm> darix: This sounds like a job for Oauth or something.
- [18:47:40] <darix>
- [18:51:25] <darix>
- [18:51:49] <darix>
that doesnt lead to good results
- [18:52:09] <darix>
sams: do you have a link for it?
- [18:53:44] <keturn>
- [18:55:28] <keturn>
the motivation for OAuth was exactly the case you describe. "I have an API, but since my web interface uses OpenID, I don't have credentials for my users which they can pass through an API anymore"
- [18:55:55] <darix>
uhm we will have the users to pass to the api.
- [18:56:03] <darix>
but users can use the api directly aswell. :)
- [18:56:33] <darix>
keturn: i am talking about and
- [19:30:51] <ronny>
- [19:31:24] <ronny>
what are the current strategies to recover from identity theft ?
- [19:35:47] <ronny>
anyone ?
<cygnus> ronny, the best place to discuss that is probably going to be the mailing list.
- [20:38:52] <ronny>
cygnus: didnt want to discuss - just have a listing
- [20:40:24] <_keturn>
OpenID identity theft, specifically?
- [20:41:37] <PibbRelay>
<cygnus> ronny, my point is that there isn't really a listing. this is the sort of thing that a discussion on would really flesh out.
- [21:03:31] * claudio\out is now known as claudio
- [21:38:41] <forsaken>
- [21:44:47] <forsaken>
neat integration!
- [21:47:10] <Makenshi>
I'm undecided what address to use as my openid on sites
- [21:47:37] <Makenshi>
what would be nice is if the sites used the destination address of the referral
- [21:47:43] <forsaken>
i'm using the one, since its done my janrain
- [21:48:03] <Makenshi>
eg,, point to
- [21:48:17] <Makenshi>
however the id consumer see them all as different identities
- [21:48:56] <Makenshi>
i have ids with janrain and verisign, and working to integrate it into one of my own sites
- [21:49:25] <forsaken>
ah, gotcha
- [21:49:48] <Makenshi>
that might not be a bad thing though..
- [21:50:08] <Makenshi>
i just dunno which one to use when i register for things
- [21:51:02] <forsaken>
are you trying to make your site an openid provider? or just somehow relay the others at your own site?
- [21:52:27] <Makenshi>
right now i have a referral to a third party site, which i may still use because the site i am setting up as an idp is not but
- [21:52:51] <Makenshi>
i think because is for my use only, it makes sense to use that
- [21:53:28] <Makenshi>
or maybe make it similar to my email address, eg, for email, for openid
- [21:53:35] <Makenshi>
so many options.. i don't know!
- [21:53:40] <forsaken>
haha, indeed
- [21:54:11] <forsaken>
at current i just have the myopenid one, i'm currently developing my personal site to accept openid's, so I haven't gotten to thinking about hosting my own
- [21:54:12] <Makenshi>
wonder if there are any sites offering an idp for domains, like google apps for email/etc
- [21:54:30] <Makenshi>
i mostly use myopenid and pip.versignlabs
- [21:54:54] <Makenshi>
i like verisign because i can associate multiple id's to one account
- [21:57:49] <Makenshi>
i pointed to, a little service that does an openid referral
- [21:58:30] <Makenshi>
for the sake of argument, it's
- [21:59:29] <forsaken>
thats cool
- [22:00:26] <Makenshi>
i'm a bit concerned though that if the operator turns bad, they could simply redirect it to their own provider
- [22:03:15] <forsaken>
- [22:03:47] <forsaken>
looks like theres code for it tho so you could setup your own redirect or something
- [22:04:00] <forsaken>
- [22:04:48] <Makenshi>
I have to find new hosting because i'm leaving my job soon and emigrating again
- [22:04:58] <Makenshi>
might go down the vps route
- [22:09:55] <forsaken>
- [22:11:08] <Makenshi>
rented virtual server, vmware or xen or kvm etc
- [22:11:40] <Makenshi>
they're cheaper than a physical server, and depending on the provider, can be more reliable
- [22:12:00] <forsaken>
ah, cool
- [22:12:05] <forsaken>
so shared hosting where you get root?
- [22:12:12] <forsaken>
bc its virtualized?
- [22:12:42] <Makenshi>
- [22:29:29] <forsaken>
good stuff
- [22:29:33] <forsaken>
is that usually as cheap as shared hosting?
- [22:31:35] <Makenshi>
can be, or not far off
- [22:32:21] <forsaken>
- [22:32:25] <forsaken>
i'll have to look into that
- [22:32:27] <Makenshi>
watch out for the ones that use horribly mangled guest operating systems though
- [22:33:02] <forsaken>
because it's a pain not being able to install stuff in my hosting setup, and I'm a pretty proficiant sysadmin (atleast i like to think so, good enough to install modules and not bork my box)
- [22:33:11] <Makenshi>
Some provide operating systems based on a particular Linux distribution, but they are not compatible with the software repositories
- [22:33:25] <forsaken>
- [22:33:28] <forsaken>
i havent looked into it
- [22:48:59] <Makenshi>
aha i see what you mean by pibb
- [22:49:01] <Makenshi>
- [22:53:01] <PibbRelay>
<ericholscher> nifty indeed :)
These logs were automatically created by OpenIDlogbot on
using a modified version of the Java IRC LogBot.