openid.nonce added

>So far I'm hearing exactly 1 person in favor, 1 against, and 1 don't care
>(myself).  If either group wants to push me over the edge one way or the
>other, speak up.

It seems like just one of many things  a consumer could want to 
transparently have passed back and forth.  It makes more sense to me to 
keep it in the return url.  If it is of interest to the identity server 
give ot a separate parameter, otherwise use the return url.

Making a note about the nonce in the API docs and using it in the example 
apps would be good though.

