Re: OpenID login

anatoly techtonik <[email protected]>
Newsgroups gmane.comp.bug-tracking.roundup.user
Message-ID <CAPkN8xKrOf7ZiG=7NCxHuH-VeddC-=pyN1XTcO2nC_wBwqgKxw@mail.gmail.com>
On Mon, Feb 10, 2014 at 4:11 PM, Kay Hayen <[email protected]> wrote:
>
> Hello Thomas,
>
>> The configuration of Python's Roundup instances are kept in a public
>> Mercurial repository, maybe just take a look at these files (and
>> possibly their history):
>>
>>
>> http://hg.python.org/tracker/python-dev/file/default/extensions/openid_login.py
>> http://hg.python.org/tracker/python-dev/file/default/lib/identify_patch.py
>> http://hg.python.org/tracker/python-dev/file/default/lib/openid2rp.py
>> http://hg.python.org/tracker/python-dev/file/default/html/user.openid.html
>>
>> http://hg.python.org/tracker/python-dev/file/default/html/user.register.html
>>
>> Maybe more, this was just a quick scan of the filenames. I suggest
>> to clone the repository and use "hg log -k openid" and
>> "hg grep --all -i openid" to find corresponding changesets and
>> files.
>
>
> Because they describe it as "heavily patched", I am kind of worried, that
> such merging is not all that easy and would require knowledge that I
> wouldn't have. I will give it a try though.
>
> Do you as a list happen to know, if these changes are standing chances of
> being upstreamed by them or you. Cause if one of you were already working on
> it, I would wait for it. And if not, I would attempt at least to conduct
> this in a form where the chances of it being mainlined are increased, except
> of course, I would be the only one to want it.

The license of b.p.o implementation is incompatible with Roundup. I also believe
that it was not tested for security at all and in spite of recent
issues with OpenID
I wouldn't consider it as an alternative

As for my implementation, it was based on famous python-openid library, but
failed attempts to merge patches that I had for it made me less enthusiastic
about time proven solution either. I also found it a little unwieldy
and big, but I
guess it could not be helped. In the end it appeared that Blogger's OpenID
implementation left a lot to be desired, and I couldn't even login myself, which
put me on hold for 5 years.

I am still interested in OpenID and OAuth stuff. But the graph of
workflow is not
trivial, so it is hard to communicate engineering decisions among people
without clear picture and evaluate security implications. This requires several
weeks of research just to outlay where the things should end in the end.
The complexity of the task is beyond part time activity, and maybe even
beyond the grip of one man army. I tried to secure some investments for R&D in
non-roundup-specific open source login server, but so far the contract is not
signed, and I am afraid that under the terms I will be forced to transmit my
copy rights to business owners even though this tech is far far away from their
core business.
-- 
anatoly t.

------------------------------------------------------------------------------
Android apps run on BlackBerry 10
Introducing the new BlackBerry 10.2.1 Runtime for Android apps.
Now with support for Jelly Bean, Bluetooth, Mapview and more.
Get your Android app in front of a whole new audience.  Start now.
http://pubads.g.doubleclick.net/gampad/clk?id=124407151&iu=/4140/ostg.clktrk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.