Do you perform any validation on the OpenID URI? -
When you are logging in to a user while using OpenID, do you have an OpenID URI (or identifier) Also do verification? Or do you handle it (eg) to the library.
DotNet openAuth manages all verification Validity Web sites need to put some open-ids to waste (For example, when XRI support was added, they do not look like URLs, and a web site that tried to break XRI as URL).
Comments
Post a Comment