Hi All,

On 9/12/05, joshua schachter <[EMAIL PROTECTED]> wrote:
> i'd like to put together a spec for letting users authorize remote
> application access without giving away their actual password.
> 
> here's a very preliminary idea:
> 
> 1) remote webapp links to, say, del.icio.us/auth?return=http://
> place.to.send.auth.key/
> 2) user ends up on a page that tells him 'grant access to http://
> place.to.send.auth.key for write/read/decline'
> 3) chooses read or write or whatever and is redirected to http://
> place.to.send.auth.key/?user=xyz&key=abc and this is logged to some
> del.icio.us database. (or maybe this should be POST)
> 4) api will accept either password or the auth key
> 
> thoughts?

The thing I don't like about these auth schemes, is that it's
web-based. Sounds stupid, but one thing that makes del.icio.us and
other services like that provide an API so great, is that they allow
development and use of non-web-apps (like cocoalicious and others).
Forcing these apps to send the user to a browser and from there back
to the app is even worse than annoying. (Not to say, that the proposed
scheme, through it's use of Redirection makes desktop apps quite hard
to do ... they'd have to accept HTTP request in order to retrieve the
auth key).
Or did I miss something, and this is totally easy?

Cheers
Benjamin
_______________________________________________
discuss mailing list
[email protected]
http://lists.del.icio.us/cgi-bin/mailman/listinfo/discuss

Reply via email to