RE: [security-services] [Fwd: Re: OpenID Mobile Profile?]

From
Scott Cantor <>
Date
2009-02-03T15:51:01+00:00
ID
004001c98617$2e9b9dd0$8bd2d970$@
Thread
RE: [security-services] [Fwd: Re: OpenID Mobile Profile?]
Paul Madsen wrote on 2009-02-03:
> I believe the concern is the possible absence of javascript for
auto-submit,
> implying a user click

FWIW, I haven't seen any without Javascript lately either, but whatever.
There's nothing productive I could say in response to that.

> yes, I agree. But, with our binding it is the IDP that sends the
> artifactresolve message to the SP , and I think thats what Nat is trying
to
> avoid have happen.

Not in the common case. You mean to send a *request* by artifact? Nobody
really does that, and mostly we use Redirect. So that's not a JavaScript
issue, that's a length limit concern, I guess?

-- Scott