Inferring return_to

VampWillow tech at vampwillow.com
Mon Jun 13 11:04:53 PDT 2005


> * The server could tell them the length of the return_to in the reply
> and they could truncate to that, but I worry about possible security
> implications of that strategy

I'd also worry that (sfaiaa) it hasn't been defined whether the OpenID
parameters go before or after any existing ones ...

Alison

= = = = = = = = = = = = = = = = = = =>>>
If you live your life sideways you won't
need to worry about what lies ahead ;-P


More information about the yadis mailing list