Re: [Snowy] OAuth in Snowy



Hey Sandy,

> Well, that won't really work unless you always use PLAINTEXT, as the
> consumer secret is part of the signature key and should be a known
> entity.
> 
> However, per the OAuth spec:
> 
> "The Consumer Secret MAY be an empty string (for example when no
> Consumer verification is needed, or when verification is achieved
> through other means such as RSA)."
> 
> Maybe that's the best approach.
> 
> Do we know if django-piston supports automatically adding new consumer
> keys that appear in requests?  Probably not...we should probably
> implement that part ourselves.

Have you guys sorted this secrets issue out yet?  Also, have you had a
chance to work on the Tomboy component of the OAuth support?  I wonder
if we can make piston support both HTTP and OAuth for the time being so
we can get this patch committed.

Best,

-Brad



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]