in
http://bugs.debian.org/602527, Jamie Mcclelland wrote:
> The problem seems to be caused by the key janrain_nonce being passed
> twice.
>
> I think trac-authopenid should detect the duplicate and only use it
> once
What if the two values differ? This seems like a bug in the openid
provider, not in the consumer. i think the consumer can legitimately
reject this situation (though arguably it should do so in a more
graceful way than the current crash/backtrace).
--dkg