On the subject of third party applications performing operations on behalf 
of users:

One could imagine using some distributed authorization technique like Kerberos
tickets to solve this problem.  For the sake of argument, imagine that
a user wants
to grant temporary read permissions to Kai's tool but doesn't want to surrender
control of his password, or even allow Kai's tool to make changes.  
He could tell
the Delicious server to write an authorization credential with the following:

 - the identity of the service
 - the operations (read)
 - a time period (ten minutes)

The Delicious service could then produce a token which, when passed from the
user to Kai's tool and back to Delicious, digitally signed by the
service, the user,
a member of the high council of Delicious Wizards, and, on Tuesdays, either
Bruce Sterling or Bruce Schneier, would give the third party web service the
indicated access.

I realize that this is extremely unlikely to happen in Delicious-land,
but it's fun
to dream, anyway.  This isn't exactly a Single Sign-On or Federated Identity
issue, but tools from that space like SAML could theoretically be used to solve
this problem.

-- 
Brian Del Vecchio   |   [EMAIL PROTECTED]   |   http://hybernaut.com/
_______________________________________________
discuss mailing list
[email protected]
http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss

Reply via email to