Marc Hughes


Home
Blog
Twitter
LinkedIn
GitHub
about
I am a developer from a bit west of Boston.

AIR + OSX + OpenId = Broken

20 Sep 2008

After a long session of debugging I've come to the conclusion that it's not possible to get OpenId working in an AIR app on OSX because of this bug. I'm not sure why I didn't run into this earlier, maybe it's a new bug.

        <p>In short, whenever the HTML control gets redirected somewhere, it loads that page twice instead of once like it should.&#160; That will likely break more than just OpenID.&#160;Hell, imagine submitting a form twice or something because of this.&#160; Luckily forms don't usually do a redirect to submit, unluckily OpenID relies on redirects to work. </p>
        <p>The specific problem arises when an OpenID provider redirects the user back to the website requesting authentication.&#160; The website loads, but then it loads again.&#160; Per the OpenID specification, that second load must be rejected by the website because it contains the same openid.response_nonce as the load that happened immiedately before it.&#160; So now we have a failure condition and authentication stops.&#160; The reason the specification states that, is because a malicious user could use a replay attack to use the same authentication token from someone else over and over again. </p>
          <p>Please, <a href="https://bugs.adobe.com/jira/secure/ViewIssue.jspa?id=72835&amp;vote=vote">go vote on that bug</a> so we can get this fixed. <br />
                  </p>
          <p>Luckily, it works fine on Windows and Linux (yeah, AIR in Linux rocks!) </p>
          <p>&#160;</p><p></p>