On the subject of third party applications performing operations on behalf of users:
One could imagine using some distributed authorization technique like Kerberos tickets to solve this problem. For the sake of argument, imagine that a user wants to grant temporary read permissions to Kai's tool but doesn't want to surrender control of his password, or even allow Kai's tool to make changes. He could tell the Delicious server to write an authorization credential with the following: - the identity of the service - the operations (read) - a time period (ten minutes) The Delicious service could then produce a token which, when passed from the user to Kai's tool and back to Delicious, digitally signed by the service, the user, a member of the high council of Delicious Wizards, and, on Tuesdays, either Bruce Sterling or Bruce Schneier, would give the third party web service the indicated access. I realize that this is extremely unlikely to happen in Delicious-land, but it's fun to dream, anyway. This isn't exactly a Single Sign-On or Federated Identity issue, but tools from that space like SAML could theoretically be used to solve this problem. -- Brian Del Vecchio | [EMAIL PROTECTED] | http://hybernaut.com/ _______________________________________________ discuss mailing list [email protected] http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss

