Skip to Content.
Sympa Menu

en - [sympa-users] Re: Re: sympa and openid

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: Graham Todd <address@concealed>
  • To: address@concealed
  • Subject: [sympa-users] Re: Re: sympa and openid
  • Date: Tue, 26 Jun 2007 22:50:26 -0400

address@concealed wrote:
> Graham Todd wrote:
>> Has anyone been experimenting with integrating openid and sympa?
>>
>> I'm not sure openid would be appropriate for user logins and management
>> of a list - but perhaps an existing sympa installation could be
>> "shoehorned" into a role as an OpenID provider?
>>
>> Any thoughts?
>>
> We don't but we are really interested with that issue because we are
> involved in identity federation project and openId is a technology we
> want to experiment.
>
> Any feed back about needs or usage are welcome.

Leveraging a large installed base of mailing list users to create an
openid *provider* is interesting, but I don't know if it is possible or
desirable. It certainly would have to be turned off by default :-)
OpenID does raise interesting points of discussion for authentication
security etc. that are best left to experts.

It could be a useful "feature" for sympa to have "login via openid". My
impression is that various openid tool makers are trying to make
implementing support for this easier using various openid libraries. A
few of the web frameworks are building in openid too - I know catalyst
http://www.catalystframework.org/ has an OpenID::Auth module of some
kind (maybe catalyst would make a nice web frontend for sympa heheh!).
sxip.org used to have a perl implementation of an openid/sxip *provider*
(sxip and openid are merging or merged now I believe).

I think if each user of a sympa installation had their own unique
"homepage" where openid attributes were published that would be a start
on implementing openid. (??) Right now sympa users have no unique URI to
changes prefs etc. Instead one logs in and visits a URL like:

http://some-sympa-site.org/pref

I think probably something like:

http://some-sympa-site.org/users/username

would be required or maybe:

http://some-sympa-site.org/users/username/contact

But that would be only if sympa were able to act as an openid provider.
Supporting openid logins from other provider's URIs might be easier.

some refs:

http://dev.aol.com/article/2007/05/openid_blog
http://search.cpan.org/~miyagawa/Catalyst-Plugin-Authentication-Credential-OpenID-0.02/
http://search.cpan.org/~bradfitz/Net-OpenID-Server-0.11/

--
G. Todd - bellanet.org






Archive powered by MHonArc 2.6.19+.

Top of Page