<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>CuppaDev - Latest Comments in Cuppadev &amp;raquo; OpenID in RailsCollab</title><link>http://cuppadev.disqus.com/</link><description></description><language>en</language><lastBuildDate>Sat, 11 Aug 2007 19:12:00 -0000</lastBuildDate><item><title>Re: Cuppadev &amp;raquo; OpenID in RailsCollab</title><link>http://www.cuppadev.co.uk/oldbrew/openid-in-railscollab/#comment-2429590</link><description>Actually, you don't even need to give them a username. Their OpenID can become the "username identifier".  Most OpenID oriented consumers do this.  Jyte, Pibb, Zooomr, Ma.gnolia, etc.&lt;br&gt;&lt;br&gt;Now, there is a "best practices" recommendation where you should allow any given "user" (in terms of one person) the ability to link multiple OpenIDs, or set a plain 'ole username and password, in case their OpenID Identity Provider is down.&lt;br&gt;&lt;br&gt;I personally would rather go with additional factor authentication.  Simple (private'ish) profile questions that only come into play when a provider does not resolve.&lt;br&gt;&lt;br&gt;That's just me, though.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jason</dc:creator><pubDate>Sat, 11 Aug 2007 19:12:00 -0000</pubDate></item><item><title>Re: Cuppadev &amp;raquo; OpenID in RailsCollab</title><link>http://www.cuppadev.co.uk/oldbrew/openid-in-railscollab/#comment-2429591</link><description>Jason,&lt;br&gt;&lt;br&gt;I partly followed the "best practices" concept and just made each user have an OpenID field which is checked against when logging in via OpenID.&lt;br&gt;&lt;br&gt;Although i didn't go so far as to allow them to have multiple OpenID's, as considering they could still login with a regular username + password it seemed a bit silly.&lt;br&gt;&lt;br&gt;IMO, if one wants to use multiple OpenID providers with a single app, they should just setup their own OpenID page which links to any one of the various providers they want to use.&lt;br&gt;&lt;br&gt;Regards,&lt;br&gt;&lt;br&gt;James</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">James Urquhart</dc:creator><pubDate>Sat, 11 Aug 2007 19:12:00 -0000</pubDate></item><item><title>Re: Cuppadev &amp;raquo; OpenID in RailsCollab</title><link>http://www.cuppadev.co.uk/oldbrew/openid-in-railscollab/#comment-2429592</link><description>Awesome to hear that you've added support!&lt;br&gt;&lt;br&gt;You should also take a look at OAuth... "OpenID for APIs" in a sense... or a kind of generalized FlickrAuth. We've been building this out for the last several months to solve problems that both Ma.gnolia and Twitter have had in either getting OpenID to work on the desktop side (Ma.gnolia Dashboard Widget support for OpenID) or on the API side (Twitter's various mashups that ask for your Twitter username and password).&lt;br&gt;&lt;br&gt;Basecamp currently exposes a limitation of OpenID in that it assigns you a username and password to access your protected RSS feeds... instead, Basecamp should grant external applications a token that allows for user-controlled access to their data. OAuth provides the protocol to solve that exact problem.&lt;br&gt;&lt;br&gt;&lt;a href="http://groups.google.com/group/oauth" rel="nofollow"&gt;http://groups.google.com/group/oauth&lt;/a&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Chris Messina</dc:creator><pubDate>Sat, 11 Aug 2007 19:12:00 -0000</pubDate></item></channel></rss>