Google Groups Home
Help | Sign in
Message from discussion specify OAuth for the viewer or the owner, in gadgets.io.makeRequest
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
humbroll  
View profile
 More options May 20, 9:56 pm
From: humbroll <humbr...@gmail.com>
Date: Tue, 20 May 2008 18:56:24 -0700 (PDT)
Local: Tues, May 20 2008 9:56 pm
Subject: Re: specify OAuth for the viewer or the owner, in gadgets.io.makeRequest
Of course, using owners token is DEFAULT even viewer's access token
would be available.
And specifing "gadgets.io.RequestParameters.OAUTH_USER" is OPTIONAL.
That's backwards compitable i think.

Thanks for your feedback in advance.

On May 21, 3:59 am, "Brian Eaton" <bea...@google.com> wrote:

> On Tue, May 20, 2008 at 4:07 AM, humbroll <humbr...@gmail.com> wrote:
> >> - how should the gadget rendering server decide whether a particular
> >> user is allowed to use an OAuth access token issued to another user?
> > i think it is matter of gadget implementation.
> > If makeRequest is invoked with V's access_token, there is no problem.
> > because V just does oauth authentication according to opensocial
> > specification.

> Let me see if I understand: both the viewer's and the owner's access
> tokens would be available to the gadget.

> That's not backwards compatible with what we have today, where only
> the owner's access token is ever used.  If someone has written a
> gadget that (for security reasons) depends on the viewers token not
> being usable, that gadget would become insecure by virtue of this
> change.

> In general I'm suspicious of changes that are not backwards compatible.

> Cheers,
> Brian


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2008 Google