Re: OpenID Trusted Authentication Extension

2007-08-31 Thread James Henstridge
On 31/08/2007, John Ehn <[EMAIL PROTECTED]> wrote: > Well, I've slept on it. I think we have a difference in philosophy. > > The other Extesions - AX, Simple Registration, etc. - follow the same data > flow methodology: > > RP -> UA -> OP > RP <- UA <- OP With my proposed workflow, it'd be going

OpenID Trusted Authentication Extension

2007-08-31 Thread John Ehn
I think I see where there might be confusion. When the initial request occurs, we're actually doing a re-authentication with the client site. So we're sending a check_id request with the return_to pointing to the client site. Because we have some extra arguments (including the URL of the destin

Re: OpenID Trusted Authentication Extension

2007-08-31 Thread John Ehn
Well, I've slept on it. I think we have a difference in philosophy. The other Extesions - AX, Simple Registration, etc. - follow the same data flow methodology: RP -> UA -> OP RP <- UA <- OP I believe I'm sticking to the same principles in my spec. We are doing the very same thing when we coll