Gmail Calendar Documents Reader Web more »
Recently Visited Groups | Help | Sign in
Google Groups Home
OAuth functionality partially restored
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  1 message - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Matt Sanford  
View profile  
(1 user)  More options Apr 23 2009, 4:50 pm
From: Matt Sanford <m...@twitter.com>
Date: Thu, 23 Apr 2009 13:50:06 -0700
Local: Thurs, Apr 23 2009 4:50 pm
Subject: OAuth functionality partially restored
Hello everybody,

    We were forced to disable OAuth [1] after a security vulnerability  
[2][3] was found in the OAuth protocol. As part of the fixes for this  
problem there have been some changes to the OAuth functionality. The  
relevant changes are:

1. The lifetime of a Request Token is now shorter. This new time limit  
should be long enough for a person to complete the flow, but short  
enough that it cuts off attacks. This does not effect access tokens  
and should be totally transparent to OAuth enabled applications.

2. The oauth_callback parameter is now ignored. Users will be  
redirected to the callback registered when the application was  
created. We're currently working on changes that will re-enable this  
feature but felt that OAuth should be available without this parameter  
while that work takes place.

     We're very sorry for the silence during this problem but due to  
the security implications all OAuth vendors were asked to keep the  
details secret until the official announcement. Hopefully we'll have a  
replacement for the oauth_callback available in the near future.

Thanks;
   – Matt Sanford / @mzsanford
       Twitter API Developer

[1] - http://blog.twitter.com/2009/04/whats-deal-with-oauth.html
[2] - http://oauth.net/advisories/2009-1
[3] - http://www.hueniverse.com/hueniverse/2009/04/explaining-the-oauth-ses...


    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2010 Google