Thursday, 2 June 2011

Unlucky day for OpenID

Tried today some small changes in cl-openid and faced various problems (in 3rd parties! verified it by unchanged cl-openid and also by testing with other online services).

Blogger OpenID provider is just broken (http://www.google.com/support/forum/p/blogger/thread?tid=120fff3e2b1a061d&hl=en)

Livejournal OpenID provider started to violate the spec (as I read it) by returning error response with HTTP status code 200 OK. (See 5.1.2.2. Error Responses in the end of this section: http://openid.net/specs/openid-authentication-2_0.html#direct_comm and 8.2.4. Unsuccessful Response Parameters in the end of this section: http://openid.net/specs/openid-authentication-2_0.html#anchor20). When I tested Livejournal with cl-openid last time, it worked OK.

Update: Livejournal problem is solved by workaround in cl-openid. Blogger remains broken (including work with any other OpenID relying parties, not only cl-openid).