3 ms·
that's a great chart, but a few corrections about OpenID: Provider must stay online at all times: the OpenID provider needs to be online when you login to the
by anarcat 10y ago
that's a great chart, but a few corrections about OpenID:
Provider must stay online at all times: the OpenID provider needs to be online when you login to the consumer site, after that, you have a session with that site and the provider doesn't need to be online.
Requires Javascript: there's a fallback in OpenID.
Ability to contact owner: there are extensions to propagate attributes like email addresses that are commonly supported.
- cdcarter 10y agoI think the key point is that by design, OpenID Connect doesn't necessitate that the identity provider reveals the users email address to the service provider. The identity provider can choose to include that in the token (or the UserInfo endpoint) or they can hide it behind another OAuth scope and explicit permission. Whereas by design, Persona does mean the service provider has access to your email address. For consumer applications, this is probably fine, but it's a very different assumption than most access and authorization use.