AOL openid 网站验证
我正在尝试使用 AOL openid,但我收到“AOL 无法验证此网站”
有人可以告诉我避免此错误的步骤吗?我应该做什么。
如果有一些示例代码,请分享 - 提前致谢
此致,
Navin
George,谢谢您你回答,但是我在让它工作时遇到问题,我的 xrds 文件如下
<?php
header('Content-type: application/xrds+xml');
$xrdstext = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n";
$xrdstext =$xrdstext . "<xrds:XRDS";
$xrdstext =$xrdstext ." xmlns:xrds=\"xri://$xrds\"";
$xrdstext =$xrdstext ." xmlns:openid=\"http://openid.net/xmlns/1.0\"";
$xrdstext =$xrdstext ." xmlns=\"xri://$xrd*($v*2.0)\">\n";
$xrdstext =$xrdstext ."<XRD>\n";
$xrdstext =$xrdstext ."<Service xmlns=\"xri://$xrd*($v*2.0)\">\n";
$xrdstext =$xrdstext ."<Type>http://specs.openid.net/auth/2.0/return_to</Type>\n";
$xrdstext =$xrdstext ."<URI>http://localhost:56709/myproject/socialoauth.aspx</URI>\n";
$xrdstext =$xrdstext ."</Service>\n";
$xrdstext =$xrdstext ."</XRD>\n";
$xrdstext =$xrdstext ."</xrds:XRDS>";
echo $xrdstext;
?>
,我的请求 url 是
我不确定我做错了什么
请帮忙...
Iam trying to use AOL openid, nut am getting "AOL is unable to verify this website"
can somebody tell me the steps to avoid this error, what should I don on my end.
If there is some sample code please share it - thanks in advance
Regards,
Navin
George thank you for you answer, however I have issue in make it work, my xrds file as follows
<?php
header('Content-type: application/xrds+xml');
$xrdstext = "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n";
$xrdstext =$xrdstext . "<xrds:XRDS";
$xrdstext =$xrdstext ." xmlns:xrds=\"xri://$xrds\"";
$xrdstext =$xrdstext ." xmlns:openid=\"http://openid.net/xmlns/1.0\"";
$xrdstext =$xrdstext ." xmlns=\"xri://$xrd*($v*2.0)\">\n";
$xrdstext =$xrdstext ."<XRD>\n";
$xrdstext =$xrdstext ."<Service xmlns=\"xri://$xrd*($v*2.0)\">\n";
$xrdstext =$xrdstext ."<Type>http://specs.openid.net/auth/2.0/return_to</Type>\n";
$xrdstext =$xrdstext ."<URI>http://localhost:56709/myproject/socialoauth.aspx</URI>\n";
$xrdstext =$xrdstext ."</Service>\n";
$xrdstext =$xrdstext ."</XRD>\n";
$xrdstext =$xrdstext ."</xrds:XRDS>";
echo $xrdstext;
?>
and my request url is
am not sure what am doing wrong
please help...
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
因此,出现此错误的原因是 AOL 无法验证依赖方 return_to URL(根据 OpenID 2 规范的第 13 节 [http://openid.net/specs/openid-authentication-2_0.html#rp_discovery])。执行此步骤是为了保护用户免受指定领域与 return_to URL 不匹配的攻击。
要消除此错误,您需要通过指定的领域字符串支持 XRDS 发现。根据屏幕截图,这仅意味着向本地主机上运行的服务器添加支持。
基本上,对 http://localhost:56709 的 HTTP 请求(带有 application/xrds+xml 的 Accept HTTP 标头)应该返回X-XRDS-Location 的响应 HTTP 标头,其值指定 XRDS 文件的位置,也可以直接返回 XRDS 文档。
XRDS 文档应如下所示...
注意:对本地主机的 HTTP 请求将失败,因为无法到达该站点。该警告将持续存在,直至 XRDS 文档部署到可访问的站点。
So the reason for this error is that AOL is unable to verify the Rely Party return_to URL (per section 13 of the OpenID 2 spec [http://openid.net/specs/openid-authentication-2_0.html#rp_discovery]). This step is performed to protect the user from an attack where the realm specified doesn't match the return_to URL.
To get rid of this error, you need to support XRDS discovery via the specified realm string. Based on the screenshot, this just means adding support into the server running on localhost.
Basically, an HTTP request to http://localhost:56709 with an Accept HTTP header of application/xrds+xml should return either a response HTTP header of X-XRDS-Location with a value specifying the location of the XRDS file, or it can return the XRDS document directly.
The XRDS document should look something like this...
NOTE: HTTP requests to localhost will fail as it's not possible to reach that site. The warning will continue until the XRDS document is deployed to a reachable site.