Re: [Snowy] OAuth 1.0a



On Fri, Mar 19, 2010 at 10:26 AM, Cornelius Hald <hald icandy de> wrote:
> On Fri, 2010-03-19 at 10:15 -0700, Sandy Armstrong wrote:
>> On Fri, Mar 19, 2010 at 9:56 AM, Cornelius Hald <hald icandy de> wrote:
>> > On Fri, 2010-03-19 at 10:41 -0600, Andres Vargas - zodman wrote:
>> >> for the oath check the django-piston app .. it implement oath support on snowy
>> >
>> > Ok, I didn't check the code. But if this bug report is correct, 1.0a is
>> > not yet supported.
>> > http://bitbucket.org/jespern/django-piston/issue/66/oauth-10a-support
>>
>> It is correct.  Is this an issue for Conboy?  Tomboy supports both 1.0 and 1.0a.
>
> I'm only supporting 1.0a in Conboy. Originally I had 1.0 support when
> testing with Snowy, then later to get it working with U1 I just changed
> to 1.0a without keeping compatibility. I thought that Snowy probably
> will switch to 1.0a soon, because 1.0 is AFAIK considered insecure.

Yes.  The reason I was waiting on the Piston developers is that they
seemed to have some sort of idea for how they wanted to architect
this, and they said they'd be working on it a few months ago, yadda
yadda yadda.  But their priorities seem to have shifted so we should
go ahead and do it ourselves.

> Someone just asked me whether or not he can use Snowy with Conboy, so I
> thought I should check with your first.
>
> I could add 1.0 support back to Conboy of course, but if Snowy will
> switch eventually to 1.0a I think, I'll just wait it out :)

If you're doing that, it gives me even more reason to add 1.0a support
to Piston. ;-)  Conboy is an ideal use case for Snowy sync and I don't
want any hurdles in the way of your users.

Sandy


[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]