<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en">
	<title type="text">Comments for hueniverse</title>
	<subtitle type="text">Thoughts on Technology, Standards, and the Open Web</subtitle>

	<updated>2012-01-27T19:07:05Z</updated>

	<link rel="alternate" type="text/html" href="http://hueniverse.com" />
	
	<id>http://hueniverse.com/comments/feed/atom/</id>
<generator uri="http://wordpress.org/" version="3.3.1">WordPress</generator>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Hueniverse-Comments" /><feedburner:info uri="hueniverse-comments" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
		<title>Comment on Protocol Workflow by Oleg Derid</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/GVJ0wsyMS8I/" type="text/html" />

		<author>
			<name>Oleg Derid</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37681</id>
		<updated>2012-01-27T19:07:05Z</updated>
		<published>2012-01-27T19:07:05Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37681">&lt;p&gt;Great example.&lt;/p&gt;
&lt;p&gt;From privacy point of view i would not like Beepa to fetch all my photos from Faji. We can see that Beepa fetches all photos, so from client perspective there is a concern that Beepa could fetch and catch on server side photos i wouldn&amp;#8217;t like them to show.&lt;/p&gt;
&lt;p&gt;I think there is an architectural way to solve this problem:&lt;br /&gt;
   a. explicitly restrict some photos on Faji side (make them private, so that external party like Beepa can&amp;#8217;t fetch them).&lt;br /&gt;
   b. when granting authorization on Faji side choose which photos to share.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/GVJ0wsyMS8I" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042" href="http://hueniverse.com/oauth/guide/workflow/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37681</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by craig</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/ca4PAVwbBlc/" type="text/html" />

		<author>
			<name>craig</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37620</id>
		<updated>2012-01-25T19:11:51Z</updated>
		<published>2012-01-25T19:11:51Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37620">&lt;p&gt;fantastic &amp;#8211; I appreciated that you took the time to explain concepts like hashing and utf-8 encoding along the way. Excellent article!&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/ca4PAVwbBlc" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37620</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/1S08E5JpdYk/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37611</id>
		<updated>2012-01-25T15:46:39Z</updated>
		<published>2012-01-25T15:46:39Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37611">&lt;p&gt;I&amp;#8217;m not familiar with Fanpage but if they provider an OAuth API to do this, you can register a client with them and perform normal OAuth authorization on your server then post to their status update.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/1S08E5JpdYk" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37571" href="http://hueniverse.com/questions/#comment-37571" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37611</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Marcel Gringo</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/j1wDrbnd7yo/" type="text/html" />

		<author>
			<name>Marcel Gringo</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37571</id>
		<updated>2012-01-24T09:44:11Z</updated>
		<published>2012-01-24T09:44:11Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37571">&lt;p&gt;Hi &amp;#8230; Question:&lt;/p&gt;
&lt;p&gt;I want to make an App on a Fanpage where people can write there experience on a  service. when published &amp;#8230; this experience is also posted on there own timeline as their status update &amp;#8230;&lt;/p&gt;
&lt;p&gt;Is this possible with OAuth ?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/j1wDrbnd7yo" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37571</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/3Ofxvn4Bu3Y/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37566</id>
		<updated>2012-01-24T06:40:40Z</updated>
		<published>2012-01-24T06:40:40Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37566">&lt;p&gt;Not sure.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/3Ofxvn4Bu3Y" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526#comment-37555" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37566</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/PUbo75tMqRk/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37565</id>
		<updated>2012-01-24T06:40:26Z</updated>
		<published>2012-01-24T06:40:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37565">&lt;p&gt;Plan, yeah. In practice, the app source needs some cleaning up so it is a question of when I get around to it.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/PUbo75tMqRk" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526#comment-37554" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37565</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/95NKNedrr_Q/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37564</id>
		<updated>2012-01-24T06:39:34Z</updated>
		<published>2012-01-24T06:39:34Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37564">&lt;p&gt;That depends on how the client chooses to implement it. They can keep the access token and look it up using a session cookie. Also, the provider can also automatically redirect back without prompting the user to do it again.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/95NKNedrr_Q" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042#comment-37507" href="http://hueniverse.com/oauth/guide/workflow/#comment-37507" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37564</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Ron Heiney</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/b7ICq4e4d5k/" type="text/html" />

		<author>
			<name>Ron Heiney</name>
			
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37555</id>
		<updated>2012-01-23T17:01:33Z</updated>
		<published>2012-01-23T17:01:33Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555">&lt;p&gt;Does the Facebook authentication work with localhost:8000, I was able to log in with twitter.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/b7ICq4e4d5k" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Ron Heiney</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/zEjlwhUXtDs/" type="text/html" />

		<author>
			<name>Ron Heiney</name>
			
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37554</id>
		<updated>2012-01-23T15:45:08Z</updated>
		<published>2012-01-23T15:45:08Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554">&lt;p&gt;&amp;#8220;including the soon to be open sourced iPhone app we never got to release&amp;#8221; Is the plan to still release the mobile app?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/zEjlwhUXtDs" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by Okeke Emmanuel</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/z1ygXstBKps/" type="text/html" />

		<author>
			<name>Okeke Emmanuel</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37552</id>
		<updated>2012-01-23T11:57:25Z</updated>
		<published>2012-01-23T11:57:25Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37552">&lt;p&gt;Many thanks.&lt;br /&gt;
I believe this will help me on something i&amp;#8217;m currently working on. &lt;img src='http://hueniverse.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/z1ygXstBKps" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37552</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Eddie</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/9pXlsInLplc/" type="text/html" />

		<author>
			<name>Eddie</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37507</id>
		<updated>2012-01-21T09:09:03Z</updated>
		<published>2012-01-21T09:09:03Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37507">&lt;p&gt;Great demostration. But what happens if she revisits Beppa again? Does she have to go through the same process?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/9pXlsInLplc" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042" href="http://hueniverse.com/oauth/guide/workflow/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37507</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by paul</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/8M7gDwEaTRI/" type="text/html" />

		<author>
			<name>paul</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37490</id>
		<updated>2012-01-20T15:14:52Z</updated>
		<published>2012-01-20T15:14:52Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37490">&lt;p&gt;thanks for taking the time to write this article. i had to read some of twiters oauth stuff to get to a point where i understood this article, but that just shows how concise it was. thank you.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/8M7gDwEaTRI" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37490</feedburner:origLink></entry>
	<entry>
		<title>Comment on Introduction by Dhaval</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/tEZz6AzAOFE/" type="text/html" />

		<author>
			<name>Dhaval</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1027#comment-37458</id>
		<updated>2012-01-19T11:10:34Z</updated>
		<published>2012-01-19T11:10:34Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/intro/#comment-37458">&lt;p&gt;Best example of &amp;#8220;Luxury Car&amp;#8217;s Valet key&amp;#8221;&lt;br /&gt;
short and easy to understand primary thing of OAuth.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/tEZz6AzAOFE" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1027" href="http://hueniverse.com/oauth/guide/intro/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/intro/#comment-37458</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/VJDvaafL8Ok/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37356</id>
		<updated>2012-01-13T16:11:10Z</updated>
		<published>2012-01-13T16:11:10Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37356">&lt;p&gt;These decisions are all part of the provider&amp;#8217;s architecture and all options mentioned are perfectly valid. I would optimize the user experience to make the most sense.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/VJDvaafL8Ok" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37313" href="http://hueniverse.com/questions/#comment-37313" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37356</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/4oqk6zJW22w/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37355</id>
		<updated>2012-01-13T16:09:26Z</updated>
		<published>2012-01-13T16:09:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37355">&lt;p&gt;Sorry but I am unable to assist with any particular vendor. You should reach out to Yahoo! for support.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/4oqk6zJW22w" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37315" href="http://hueniverse.com/questions/#comment-37315" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37355</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/atV311FwyD0/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37354</id>
		<updated>2012-01-13T16:08:52Z</updated>
		<published>2012-01-13T16:08:52Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37354">&lt;p&gt;Sorry but I am unable to assist with any particular vendor. You should reach out to them for support.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/atV311FwyD0" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37296" href="http://hueniverse.com/questions/#comment-37296" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37354</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by liby mathew</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/HSJwPXjLgOM/" type="text/html" />

		<author>
			<name>liby mathew</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37315</id>
		<updated>2012-01-12T03:57:53Z</updated>
		<published>2012-01-12T03:57:53Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37315">&lt;p&gt;I am trying to access Yahoo&amp;#8217;s contact API and I&amp;#8217;m not able to get request token by giving URI request using my consumer key and secret.It is showing &amp;#8220;file not found&amp;#8221; while giving request.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/HSJwPXjLgOM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37315</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by tony kerz</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/0m5IQTiscwM/" type="text/html" />

		<author>
			<name>tony kerz</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37313</id>
		<updated>2012-01-12T02:59:58Z</updated>
		<published>2012-01-12T02:59:58Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37313">&lt;p&gt;hi eran, &lt;/p&gt;
&lt;p&gt;congrats on your new job and good luck @ walmart!&lt;/p&gt;
&lt;p&gt;i&amp;#8217;m working on a project where we are trying to use oauth (2) for authentication (click this button to sign in using your &amp;#8216;xyz-oauth-provider&amp;#8217; account). &lt;/p&gt;
&lt;p&gt;in this use-case, the client (user) enacts the oauth handshake with the provider, is prompted to login to the provider, is prompted to grant access to some scope of provider resources, and if all goes well, the client successfully gets an access token and uses it to call an api at the provider to get some basic account information which it uses to set up a local session. &lt;/p&gt;
&lt;p&gt;when the client&amp;#8217;s local session is complete it &amp;#8216;goes away&amp;#8217; meaning it tosses the access token. &lt;/p&gt;
&lt;p&gt;when the same user comes back (say the next day after the session with the provider has expired) via the client to run through the same process again, they are prompted to login to the provider again, but they are also prompted to grant access again. &lt;/p&gt;
&lt;p&gt;my initial instinct is that the provider should *not* prompt the user to grant access again (and let&amp;#8217;s just simplify the question for now by saying that the initial grant should have no expiration so that the refresh flow isn&amp;#8217;t in play). &lt;/p&gt;
&lt;p&gt;ok, so that is the setup for my question which is: &lt;/p&gt;
&lt;p&gt;does the spec cover this situation in terms of specifying how a provider should behave in this case? &lt;/p&gt;
&lt;p&gt;i.e. is it the client&amp;#8217;s responsibility to hold onto an access token and not ask for one twice (in which case i&amp;#8217;m unclear how to do repetitive sign-on&amp;#8217;s using oauth),&lt;br /&gt;
*or* is it the provider&amp;#8217;s responsibility to not prompt the same user if they have already granted access (and possibly return the same access token that they were initially issued). &lt;/p&gt;
&lt;p&gt;i hope my questions are relatively clear, but i&amp;#8217;d be happy to clarify if not. &lt;/p&gt;
&lt;p&gt;thanks! tony&amp;#8230;&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/0m5IQTiscwM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37313</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Kirti Patel</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/s9Kc7Si1N8s/" type="text/html" />

		<author>
			<name>Kirti Patel</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37296</id>
		<updated>2012-01-11T12:04:40Z</updated>
		<published>2012-01-11T12:04:40Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37296">&lt;p&gt;Hi, I am trying to implement twitter OAuth for my application but am running into errors every time i try. I have downloaded and am using the library of Abraham OAuth coding. At the moment every time i run my application it presents me with a link to sign into twitter but when clicked gives me the error message &amp;#8221; Cannot sign into twitter, try again later&amp;#8221; which is the error handling message of course, but i don&amp;#8217;t understand why i am being faced with this&amp;#8230;any help please? Other attempts of OAuth have taken me to the twitter website and given me the message that there are no request token for this page, but the token information has been added into the coding already. Help would be much appreciated. Thanks&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/s9Kc7Si1N8s" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37296</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/T8TualAA8sg/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37277</id>
		<updated>2012-01-10T15:55:26Z</updated>
		<published>2012-01-10T15:55:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37277">&lt;p&gt;Sorry, but I don&amp;#8217;t know much about this environment.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/T8TualAA8sg" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37246" href="http://hueniverse.com/questions/#comment-37246" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37277</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Marco Peschiera</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/UuShqqiaCTg/" type="text/html" />

		<author>
			<name>Marco Peschiera</name>
			<uri>http://www.sitohd.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37246</id>
		<updated>2012-01-08T17:49:19Z</updated>
		<published>2012-01-08T17:49:19Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37246">&lt;p&gt;I&amp;#8217;m using classic ASP and need to make OAUTH with YAHOO to get contact of a user that allow my app.&lt;br /&gt;
I can make working arriving to get a token but i can&amp;#8217;t make the api request because yahoo api is HTTP and not HTTPS so i must use oauth_signature_method =&amp;#8221;HMAC-SHA1&amp;#8243;&lt;br /&gt;
I can&amp;#8217;t get a script function that create me this oauth_signature in CLASSIC ASP.&lt;br /&gt;
Can you help me ?&lt;br /&gt;
Thanks,&lt;br /&gt;
Marco&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/UuShqqiaCTg" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37246</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer-Lahav</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/n5FJ2qY2__I/" type="text/html" />

		<author>
			<name>Eran Hammer-Lahav</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37083</id>
		<updated>2011-12-31T09:16:55Z</updated>
		<published>2011-12-31T09:16:55Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37083">&lt;p&gt;Not sure what exactly you are asking but if the roles are carried by separate entities, they need to coordinate the grants. How to accomplish that is case-specific.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/n5FJ2qY2__I" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-36861" href="http://hueniverse.com/questions/#comment-36861" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37083</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Aakash Wasnik</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/Sld4XOfabXc/" type="text/html" />

		<author>
			<name>Aakash Wasnik</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-36861</id>
		<updated>2011-12-22T00:16:19Z</updated>
		<published>2011-12-22T00:16:19Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-36861">&lt;p&gt;In case Authorization Server and Resource Server are implemented separately (unlike Facebook or Twitter where Authorization Server and Resource Server are same) &lt;/p&gt;
&lt;p&gt;Would you please throw some light on validation needs to be done at Resource Server before allowing access to REST API &lt;/p&gt;
&lt;p&gt;1. Let say In Access token validation response Authorization Server would say that Access token is issued to &amp;#8220;Client 1&amp;#8243; , Scope values are &amp;#8220;XYZ PQR&amp;#8221; and Some Resource Owner identifier such as userid&lt;br /&gt;
2. OAuth Client needs to register at Resource Server as well so that it can trust only specific OAuth clients&lt;br /&gt;
3. Also i understand that Resource Server would look at scope values as well before accessing particular REST API&lt;/p&gt;
&lt;p&gt;I would appreciate your response.&lt;/p&gt;
&lt;p&gt;Thanks&lt;br /&gt;
Aakash&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/Sld4XOfabXc" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-36861</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Eran Hammer-Lahav</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/Re7mWp0DtHM/" type="text/html" />

		<author>
			<name>Eran Hammer-Lahav</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1526#comment-36732</id>
		<updated>2011-12-15T17:44:36Z</updated>
		<published>2011-12-15T17:44:36Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-36732">&lt;p&gt;Yes, Sled / Postmile uses MAC tokens based on the last draft. A new draft is expected as soon as the WG can figure out how to proceed. You can see the current status in my github account.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/Re7mWp0DtHM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526#comment-36730" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-36730" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-36732</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Lorenzo Polidori</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/9l5eycU1eiY/" type="text/html" />

		<author>
			<name>Lorenzo Polidori</name>
			
		</author>

		<id>http://hueniverse.com/?p=1526#comment-36730</id>
		<updated>2011-12-15T17:10:08Z</updated>
		<published>2011-12-15T17:10:08Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-36730">&lt;p&gt;Hi Eran,&lt;br /&gt;
have you used MAC Access Token Authentication for the OAuth 2.0 on Sled? If this is the case, what open standard did you use?&lt;br /&gt;
The IETF draft regarding HTTP MAC access authentication scheme for OAuth 2.0 (draft-ietf-oauth-v2-http-mac-00) expired on 12 November 2011 and the IETF tracker tool doesn&amp;#8217;t tell whether this proposal has been dropped or there has been a follow-up.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/9l5eycU1eiY" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-36730</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer-Lahav</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/cc8yAAgbMmE/" type="text/html" />

		<author>
			<name>Eran Hammer-Lahav</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-36713</id>
		<updated>2011-12-14T05:46:22Z</updated>
		<published>2011-12-14T05:46:22Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-36713">&lt;p&gt;The code was sent through the client via a redirection to the attacker&amp;#8217;s site.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/cc8yAAgbMmE" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-36708" href="http://hueniverse.com/questions/#comment-36708" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-36713</feedburner:origLink></entry>
	<entry>
		<title>Comment on Is the Party Winding Down at Facebook? by Eran Hammer-Lahav</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/YjspabSnHns/" type="text/html" />

		<author>
			<name>Eran Hammer-Lahav</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1520#comment-36712</id>
		<updated>2011-12-14T05:45:10Z</updated>
		<published>2011-12-14T05:45:10Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36712">&lt;p&gt;I&amp;#8217;ve never questioned the caliber of talent at Facebook. I even blogged about it grudgingly&amp;#8230; But from where I stand, I no longer hear the same level of excitement. People are still in awe of the team but no longer ooh and ah about it the way they used to.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/YjspabSnHns" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1520#comment-36710" href="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36710" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36712</feedburner:origLink></entry>
	<entry>
		<title>Comment on Is the Party Winding Down at Facebook? by Luke Shepard</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/8MLr_BU6xac/" type="text/html" />

		<author>
			<name>Luke Shepard</name>
			<uri>http://www.lukeshepard.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1520#comment-36710</id>
		<updated>2011-12-14T03:41:08Z</updated>
		<published>2011-12-14T03:41:08Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36710">&lt;p&gt;I&amp;#8217;ve worked at Facebook for 4.5 years and I&amp;#8217;m still quite excited. My outlook may be rosier than most because I&amp;#8217;m working on the forefront of the mobile web ecosystem, but I don&amp;#8217;t think it&amp;#8217;s that atypical. The type of person who is attracted to Facebook is typically quite talented, entrepreneurial, and has plenty of other options of stuff to do with their time. The concentration of intense talent is mostly why I love it here.&lt;/p&gt;
&lt;p&gt;But the flipside to such talent is the high opportunity cost of their Witness the myriad startups created by Facebook alum just in the past few years (Quora, Asana, Path, Pinterest, Storm8, Cloudera). As such, the opportunity cost of their time is high &amp;#8211; so it&amp;#8217;s not unexpected that after a few years, many would seek to move on.&lt;/p&gt;
&lt;p&gt;That said, it seems like there are more insanely talented people joining the company now than ever before. Just in the past few months, I&amp;#8217;ve started working with Charles Jolley and the whole Strobe team; the amazing designers from Sofa; Mike Shaver from Mozilla; James Pearce from Senscha. When this many awesome people are flooding into the company, I think it&amp;#8217;s far from winding down.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/8MLr_BU6xac" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1520" href="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36710</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Sujing</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/FvZrGi3ElE4/" type="text/html" />

		<author>
			<name>Sujing</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-36708</id>
		<updated>2011-12-14T01:55:51Z</updated>
		<published>2011-12-14T01:55:51Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-36708">&lt;p&gt;&lt;a href="http://hueniverse.com/2011/06/oauth-2-0-redirection-uri-validation/" rel="nofollow"&gt;http://hueniverse.com/2011/06/oauth-2-0-redirection-uri-validation/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;about oauth&lt;br /&gt;
In step 7：	Evil user takes the authorization code and gives it back to the client by constructing the original correct redirection URI.&lt;br /&gt;
I wonder how Evil User can take the authorization code since the code has sent to the victem?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/FvZrGi3ElE4" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-36708</feedburner:origLink></entry>
	<entry>
		<title>Comment on Is the Party Winding Down at Facebook? by Thomas Koch</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/xhsyZUu3VAM/" type="text/html" />

		<author>
			<name>Thomas Koch</name>
			<uri>http://www.koch.ro</uri>
		</author>

		<id>http://hueniverse.com/?p=1520#comment-36688</id>
		<updated>2011-12-12T18:53:43Z</updated>
		<published>2011-12-12T18:53:43Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36688">&lt;p&gt;The tools used by Facebook include PHP, Hadoop and ZooKeeper among many others. But from these tree I know that the code is big brown ball of mud, a maintainability nightmare. It would fit my picture that people get fed up over time to work with these tools.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/xhsyZUu3VAM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1520" href="http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/is-the-party-winding-down-at-facebook/#comment-36688</feedburner:origLink></entry>
</feed>

