<?xml version="1.0" encoding="UTF-8" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>ydn-auth at Yahoo! Groups</title>
    <link>http://tech.groups.yahoo.com/group/ydn-auth/</link>
    <description>Yahoo! Authenticated Web Services</description>

    <item>
      <title>bbauth - when user chooses &quot;i do not agree&quot;</title>
      <pubDate>Wed, 24 Jun 2009 15:20:57 GMT</pubDate>
      <dc:creator>hazarsemih</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/721</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/721</guid>
      <description>Hi All, I&#39;ve implemented Yahoo&#39;s BBAuth and it&#39;s working alright, but when the user chooses not to give permission and clicks &quot;I Do Not Agree&quot; button in the</description>
    </item>
    <item>
      <title>Displaying BBAuth appid Bad?</title>
      <pubDate>Mon, 15 Jun 2009 21:06:54 GMT</pubDate>
      <dc:creator>Diego</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/720</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/720</guid>
      <description>Is it bad or a security issue to  display the BBAuth &quot;appid&quot; in the query string for others to see? for example:</description>
    </item>
    <item>
      <title>Please confirm your request to join ydn-auth</title>
      <pubDate>Mon, 15 Jun 2009 21:06:15 GMT</pubDate>
      <dc:creator>hira sirojudin</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/719</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/719</guid>
      <description>Hi guys, I&#39;m trying rerun kennedy app sample. as long as  i&#39;ve not token yet, i add function login in after create BBAuthentication instance. look like this: </description>
    </item>
    <item>
      <title>Passing BBAUTH appid with Query string bad?</title>
      <pubDate>Mon, 15 Jun 2009 21:06:12 GMT</pubDate>
      <dc:creator>Diego</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/718</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/718</guid>
      <description>If I have an application and it is displaying the BBAuth appid in the query string is it a security problem? example:</description>
    </item>
    <item>
      <title>Fw: HTTP Transport error : &#39;411&#39; - &#39;Length Required&#39;; nested excepti</title>
      <pubDate>Mon, 15 Jun 2009 21:05:58 GMT</pubDate>
      <dc:creator>Hira Sirojudin</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/717</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/717</guid>
      <description>Hi All, I&#39;m facing below error during getUserData via axis transport ws. HTTP Transport error : &#39;411&#39; - &#39;Length Required&#39;; nested exception is: this is little</description>
    </item>
    <item>
      <title>Displaying BBAuth &quot;appid&quot; in querystring a security issue?</title>
      <pubDate>Wed, 10 Jun 2009 18:14:23 GMT</pubDate>
      <dc:creator>Diego Montalvo</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/716</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/716</guid>
      <description>I am building a web app with &quot;single sign on&quot; and was wondering if displaying the &quot;appid&quot; is a security issue for example: </description>
    </item>
    <item>
      <title>Re: Error: signature Mismatch</title>
      <pubDate>Thu, 04 Jun 2009 22:23:44 GMT</pubDate>
      <dc:creator>Ricardo Scattini</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/715</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/715</guid>
      <description>before make the curl call i&#39;m doing this [...] $url = urlencode($this-&gt;generateAuthURL()); curl_setopt( $ch, CURLOPT_URL, $url); [...] ...and I have the same</description>
    </item>
    <item>
      <title>Re: Error: signature Mismatch</title>
      <pubDate>Tue, 02 Jun 2009 17:58:50 GMT</pubDate>
      <dc:creator>Ryan Kennedy</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/714</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/714</guid>
      <description>... You&#39;re not calling urlencode() on any of the URL query parameters. It&#39;s entirely possible that would cause a signature verification error. -- Ryan Kennedy </description>
    </item>
    <item>
      <title>Error: signature Mismatch</title>
      <pubDate>Tue, 02 Jun 2009 17:55:23 GMT</pubDate>
      <dc:creator>Ricardo Scattini</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/713</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/713</guid>
      <description>Hi: I&#39;m developing an app in PHP to import contacts from Yahoo API throughout BBAuth. I followed carefully all the steps to generate/make the Signature. The</description>
    </item>
    <item>
      <title>Re: How is Twitter authenticating user with Yahoo! without the redir</title>
      <pubDate>Sun, 31 May 2009 21:17:44 GMT</pubDate>
      <dc:creator>Raul Macias</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/712</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/712</guid>
      <description>Probably they are not using BBAuth Maybe all they are doing is a manual HTTP request to the Yahoo AddressBook site to export the user&#39;s contact list as a CSV</description>
    </item>
    <item>
      <title>How is Twitter authenticating user with Yahoo! without the redirecti</title>
      <pubDate>Sun, 31 May 2009 17:17:52 GMT</pubDate>
      <dc:creator>Rubayeet Islam</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/711</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/711</guid>
      <description>Hi, I am trying to build an invitation tool for my web app just like Twitter&#39;s (http://twitter.com/invitations). I&#39;ve been reading about the BBAuth mechanism</description>
    </item>
    <item>
      <title>Re: Testing BBAuth -- Does https &quot;referer&quot; header element matter?</title>
      <pubDate>Fri, 29 May 2009 17:39:20 GMT</pubDate>
      <dc:creator>jbtibor@...</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/710</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/710</guid>
      <description>Hi Pete, a mock service is something you create, it behaves like you program it, so it depends only on you if it requires a new app id or it accepts your live</description>
    </item>
    <item>
      <title>Re: Testing BBAuth -- Does https &quot;referer&quot; header element matter?</title>
      <pubDate>Fri, 29 May 2009 17:00:24 GMT</pubDate>
      <dc:creator>clinicahealth</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/709</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/709</guid>
      <description>Tibor -- Have you succeeded with &quot;pointing your app to [a test site]&quot;? When we try this, we get errors, per previous emails in this thread. In order to set up</description>
    </item>
    <item>
      <title>Re: Testing BBAuth -- Does https &quot;referer&quot; header element matter?</title>
      <pubDate>Tue, 19 May 2009 20:51:29 GMT</pubDate>
      <dc:creator>Tibor</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/708</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/708</guid>
      <description>You could try setting up a mock service and point your app to that one while testing.</description>
    </item>
    <item>
      <title>Re: Testing BBAuth -- Does https &quot;referer&quot; header element matter?</title>
      <pubDate>Tue, 19 May 2009 18:16:26 GMT</pubDate>
      <dc:creator>Raul Macias</dc:creator>
      <link>http://tech.groups.yahoo.com/group/ydn-auth/message/707</link>
      <guid isPermaLink="true">http://tech.groups.yahoo.com/group/ydn-auth/message/707</guid>
      <description>I have exactly the same question: what is the best way to test Yahoo Browser Based Authentication locally? there should be a way for us developers to test this</description>
    </item>

  </channel>
</rss>
<!-- wr2.grp.sp2.yahoo.com uncompressed/chunked Tue Jul  7 08:50:12 PDT 2009 -->
