Closed (cannot reproduce)
Project:
Drupal core
Version:
7.0-rc4
Component:
openid.module
Priority:
Normal
Category:
Bug report
Assigned:
Unassigned
Issue tags:
Reporter:
Created:
23 Mar 2011 at 03:30 UTC
Updated:
13 Jul 2013 at 06:28 UTC
When an existing user seeks to add an openid served by SimpleID to his(her) account When SimpleID is version 2.0 of openid, the process never returns to Drupal, but leaves the user in the SimpleID "you are logged in" page.
I did not try to use version 1.0.
Comments
Comment #1
c960657 commentedI cannot reproduce this. Can you post some additional information?
Comment #2
c960657 commentedComment #3
Mikael Nord commentedThis happens when the XRD document or the openid.server/openid2.provider argument in the HTML identifier points the user to SimpleID via HTTP and not HTTPS. SimpleID will then redirect the user to its HTTPS version without passing the state ("s") parameter, which is a urlencoded entry that holds the return_to variable needed to send the user back to Drupal, among other things. So the easiest solution is to ensure that your XRD/HTML identifier points the user to SimpleID with a https:// URL.
Yahoo and Livejournal seems to send both GET and POST values to the provider. Since the GET-version does not get lost when SimpleID redirects to HTTPS, the users will still get returned to Drupal without problem. Maybe we should think about sending users the same way from Drupals OpenID module. However, sending just POST values is enough to follow the current OpenID spec:
http://openid.net/specs/openid-authentication-2_0.html#http_encoding