信息亭 PC 上的 OpenID

发布于 2024-10-19 06:00:06 字数 818 浏览 2 评论 0原文

使用 DotNetOpenAuth,我启用了 OpenID 登录本地体育俱乐部网站。 除了用户在家登录之外,我们俱乐部内还有一台以 kiosk 模式运行 IE 的 PC。我对这台自助服务终端 PC 存在一些安全问题。

1) 我可以以某种方式告诉身份提供商不要提供“让我保持登录状态”选项吗?或者至少对于雅虎来说,默认情况下取消选中它。
我希望它可以在扩展或其他东西中定义,但我还没有找到类似的东西。

2) 我可以轻松地从我们自己的站点注销用户,但与身份提供者的会话仍然存在。这允许信息亭 PC 上的任何人作为最后一个使用 OpenID 的人登录。 我的页面上有一个注销按钮,在信息亭 PC 上甚至可以定时激活注销按钮。我通过 Google、Yahoo 和 AOL 找到了注销 URL。我在注销过程中激活它们。
有人知道 myOpenID 的注销网址吗?也许还有其他提供商。或者更好的是,我可以像请求电子邮件一样向提供商请求网址吗?

如果它对任何人有帮助,我到目前为止找到的网址:
Google:https://www.google.com/accounts/Logout
雅虎:https://login.yahoo.com/config/login?logout=1
AOL:https://my.screenname.aol.com/_cqr/logout/mcLogout.psp

提前致谢,

Using DotNetOpenAuth I have enebled OpenID login to a local sportsclubs website.
Besides users logging in from home, we also have a PC within the club running IE in kiosk mode. I have some security concerns with this kiosk PC.

1) Can I somehow tell the identity provider not to offer the "Keep me signed in" option? Or at least for Yahoo uncheck it by default.
I am hoping it can be defined in an extension or something, but I haven't found anything like that.

2) I can easily log out a user from our own site, but the session to the identity provider remains. This allows anyone on the kiosk PC to login as the last person using OpenID.
I have a logoff button on my page, and on the kiosk PC even timed activation of the logoff button. With Google, Yahoo and AOL I have found logoff urls. I activate those as part of the logoff process.
Does anyone know a logoff url for myOpenID? and maybe other providers. Or even better can I request the url from the provider like I request the email?

If it helps anyone these the the urls I found so far:
Google: https://www.google.com/accounts/Logout
Yahoo: https://login.yahoo.com/config/login?logout=1
AOL:https://my.screenname.aol.com/_cqr/logout/mcLogout.psp

Thanks in advance,
Jan

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(2

染年凉城似染瑾 2024-10-26 06:00:06

我对您似乎将信息亭与用户正在访问的网站混合在一起这一事实感到困惑。您的信息亭是否被设置为只允许用户访问您的特定 RP?操纵您的 RP 来让用户退出他们的 OP 通常是粗鲁的,并且由于无论用户是从信息亭还是从他们的家庭计算机访问您的网站,这种操纵都会影响您的 RP,所以我不认为将您的网站自定义为如果信息亭是其唯一模式是个好主意。

最好只设置信息亭的 IE 选项,这样每次关闭浏览器时它都会清除所有 cookie。正如 Samuel 所说:也许编写一个插件,当它在您的网站上看到表明用户正在注销的 URL 时,会强制清除 cookie,以帮助那些不关闭浏览器的用户。

但我要为帮助提高客户的安全竖起两个大拇指!

I'm confused by the fact that you seem to be mixing the kiosk with the web sites users are visiting. Is your kiosk rigged to only let users visit your specific RP? Rigging your RP to log users out of their OP as well is usually rude, and since this rigging will impact your RP regardless of whether users visit your site from the kiosk or from their home computer, I don't think customizing your web site as if kiosk is its only mode is a good idea.

Better to just set up the kiosk's IE options such that it clears all cookies every time you close the browser. And as Samuel said: perhaps write a plugin that will clear cookies forcibly when it sees the URL on your web site that indicates the user is logging off, to help those users that don't close their browser.

But two thumbs up for helping increase the security of your customers!

寂寞笑我太脆弱 2024-10-26 06:00:06

由于它在信息亭中运行,您也可以更好地控制浏览器。当他们退出您的网站时,使用自定义插件清除所有浏览 cookie。这将有效地将他们从他们登录的任何 OpenID 站点中注销。

Since this is running in a kiosk you have more control over the browser as well. Use a custom plugin to clear ALL browse cookies when they log out of your site. That will effectively log them out of any OpenID site they're logged into as well.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文