4 ms·
In my opinion author should first read OpenID specifications and implement some "best practices" (http://wiki.openid.net/w/page/12995223/Relying-Party-Best-Prac
by ancymon 16y ago
In my opinion author should first read OpenID specifications and implement some "best practices" (http://wiki.openid.net/w/page/12995223/Relying-Party-Best-Practices http://wiki.openid.net/w/page/12995223/Relying-Party-Best-Pr...). Doing so might have solve his "problems". I think to make user "NOT to feel stupid" it's better to implement OpenID properly than quit it.
1. The OpenID specification suggests that user should be able to associate multiple identifiers with one account. That way if you store user's email address, he can easily add new OpenID account even after he lost/forgot his identifier.
2. You can't expect that OpenID provider has enabled extensions which give away user email. User can also decide not to provide his e-mail. If that's not provided you can ask user to fill a registration form "manually".
And by the way, I think that remembering who is your OpenID provider is still easier than remembering login and password.
- robconery 16y agoIt's a fair point - the problem is that if I'm going to ask for a user/password for a master account then... WTF do I need OpenID for? Also - in terms of reading the spec - we use JanRain/RPX so I let them worry about that.