Non-recoverable auth failure?

Martin Atkins mart at
Tue Jun 28 17:29:36 PDT 2005

Brad Fitzpatrick wrote:
> So just use post_grant=return and do your magic in that.
> I don't like the idea of introducing a new URL and specifying the security
> restrictions on what that URL can be (anything under trust_root?).

Oh, I missed the part about a new URL. That seems unnecessary.

I guess there's really nothing new here, but post_grant=close does seem
like a bit of an odd special case so I certainly wouldn't be sad to see
it go.

However, at this point it's probably just easier to leave it in there.
It's not really that hard to implement, after all.

