> Second, should we expose URLs to the openid provider? There could be a
> security implication there.

I would consider this minor, you are already naked when you use third
party authorization... ;-)

Reply via email to