<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" xml:lang="en">
	<title type="text">Comments for hueniverse</title>
	<subtitle type="text">Thoughts on Technology, Standards, and the Open Web</subtitle>

	<updated>2012-02-28T17:03:09Z</updated>

	<link rel="alternate" type="text/html" href="http://hueniverse.com" />
	
	<id>http://hueniverse.com/comments/feed/atom/</id>
<generator uri="http://wordpress.org/" version="3.3.1">WordPress</generator>
	<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/Hueniverse-Comments" /><feedburner:info uri="hueniverse-comments" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
		<title>Comment on Protocol Workflow by Franck</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/5yUE97r3-Y8/" type="text/html" />

		<author>
			<name>Franck</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-38234</id>
		<updated>2012-02-28T17:03:09Z</updated>
		<published>2012-02-28T17:03:09Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-38234">&lt;p&gt;which brings me to the following question. Let&amp;#8217;s say I&amp;#8217;ve been using the Faji site for some time and it remembers me each time I connect to it (I don&amp;#8217;t need to provide my login/password before it&amp;#8217;s keeping all needed on my computer). Would that mean, using the Beppa site to print my photos that even the first time, it would not ask me for my credential and I would in that case not be aware that I&amp;#8217;m actually providing access to my resources to a third party? I did some test with different site and I think I saw that behavior. Off course the server could be implemented in a way that the first time it would ask for the credentials, but it doesn&amp;#8217;t sounds like it&amp;#8217;s what happening in the real world.&lt;br /&gt;
insight?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/5yUE97r3-Y8" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042#comment-38228" href="http://hueniverse.com/oauth/guide/workflow/#comment-38228" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-38234</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/_8P2D7_3iQA/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-38228</id>
		<updated>2012-02-28T07:41:49Z</updated>
		<published>2012-02-28T07:41:49Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-38228">&lt;p&gt;Access tokens can last longer than 1 hour. It all depends on the server&amp;#8217;s security policy. As for the blind redirect, yes, Jane will just see her photos appear without granting access again.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/_8P2D7_3iQA" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042#comment-38201" href="http://hueniverse.com/oauth/guide/workflow/#comment-38201" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-38228</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/Jq68dori_gM/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-38227</id>
		<updated>2012-02-28T07:40:18Z</updated>
		<published>2012-02-28T07:40:18Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-38227">&lt;p&gt;Yes, it is correct. Each encoded part is concatenated together using an unencoded &amp;#038;.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/Jq68dori_gM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051#comment-38189" href="http://hueniverse.com/oauth/guide/authentication/#comment-38189" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-38227</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Franck</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/NVUjIPK88gQ/" type="text/html" />

		<author>
			<name>Franck</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-38201</id>
		<updated>2012-02-27T04:11:16Z</updated>
		<published>2012-02-27T04:11:16Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-38201">&lt;p&gt;Keeping the access token would not help much since it&amp;#8217;s valid for just 1 hour. (correct?)&lt;br /&gt;
When you say the provider (the server, Faji) can also  automatically redirect back&amp;#8230;, do you mean it can use it&amp;#8217;s own cookie (or other ways) to automatically authenticate the resource owner and redirect back to the Beppa site without loging in the Faji web-site? In that case, Jane would not know (I mean not explicitly like the first time) the second time that she gave access to the Beppa site, right?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/NVUjIPK88gQ" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042#comment-37564" href="http://hueniverse.com/oauth/guide/workflow/#comment-37564" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-38201</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by Matt</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/Pn4T0uabHrM/" type="text/html" />

		<author>
			<name>Matt</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-38189</id>
		<updated>2012-02-24T21:02:18Z</updated>
		<published>2012-02-24T21:02:18Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-38189">&lt;p&gt;Is the base string correct?&lt;br /&gt;
GET&amp;amp;http%3A%2F%&lt;/p&gt;
&lt;p&gt;The &amp;amp; after the method is not URL encoded yet the rest of the string is????&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/Pn4T0uabHrM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-38189</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/zmRf4rvWHVU/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-38034</id>
		<updated>2012-02-14T02:27:51Z</updated>
		<published>2012-02-14T02:27:51Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-38034">&lt;p&gt;Nope.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/zmRf4rvWHVU" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37997" href="http://hueniverse.com/questions/#comment-37997" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-38034</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Mike</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/wNpEttYrf9Q/" type="text/html" />

		<author>
			<name>Mike</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37997</id>
		<updated>2012-02-12T04:28:59Z</updated>
		<published>2012-02-12T04:28:59Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37997">&lt;p&gt;Is there a standard way to log out users?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/wNpEttYrf9Q" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37997</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by jeff</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/Q0UurLeOL2M/" type="text/html" />

		<author>
			<name>jeff</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37950</id>
		<updated>2012-02-09T20:24:56Z</updated>
		<published>2012-02-09T20:24:56Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37950">&lt;p&gt;Great article.  Thanks for writing this.  A good level of detail; not too lite, not too deep.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/Q0UurLeOL2M" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37950</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/7AwBRWb5rZA/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37885</id>
		<updated>2012-02-06T17:31:26Z</updated>
		<published>2012-02-06T17:31:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37885">&lt;p&gt;Not yet.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/7AwBRWb5rZA" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37878" href="http://hueniverse.com/questions/#comment-37878" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37885</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Malay</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/tqcscQdfNc8/" type="text/html" />

		<author>
			<name>Malay</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37878</id>
		<updated>2012-02-06T13:24:46Z</updated>
		<published>2012-02-06T13:24:46Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37878">&lt;p&gt;Did you get your writeup done on express with oauth, came across mention of this topic on your excellent writeup on nodejs, express and socket.io&lt;/p&gt;
&lt;p&gt;Appreciate the pointer.&lt;/p&gt;
&lt;p&gt;Thx&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/tqcscQdfNc8" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37878</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/RCwcYlM01W0/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37851</id>
		<updated>2012-02-04T22:35:11Z</updated>
		<published>2012-02-04T22:35:11Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37851">&lt;p&gt;There are plenty of books and resources on JS, but you should be able to just pick up a few of the node exmaples and run with them. &lt;a href="http://howtonode.org/" rel="nofollow"&gt;http://howtonode.org/&lt;/a&gt; is a great place to start. As for CoffeeScript, I have no experience with it, but generally don&amp;#8217;t see the point.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/RCwcYlM01W0" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37780" href="http://hueniverse.com/questions/#comment-37780" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37851</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Steven Tessler</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/5pwW1Oov1Ts/" type="text/html" />

		<author>
			<name>Steven Tessler</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37780</id>
		<updated>2012-02-01T01:14:12Z</updated>
		<published>2012-02-01T01:14:12Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37780">&lt;p&gt;Can you recommend some  sources for getting up to speed in JavaScript for node?&lt;/p&gt;
&lt;p&gt;Also, what are your thoughts about coffeescript?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/5pwW1Oov1Ts" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37780</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Oleg Derid</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/GVJ0wsyMS8I/" type="text/html" />

		<author>
			<name>Oleg Derid</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37681</id>
		<updated>2012-01-27T19:07:05Z</updated>
		<published>2012-01-27T19:07:05Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37681">&lt;p&gt;Great example.&lt;/p&gt;
&lt;p&gt;From privacy point of view i would not like Beepa to fetch all my photos from Faji. We can see that Beepa fetches all photos, so from client perspective there is a concern that Beepa could fetch and catch on server side photos i wouldn&amp;#8217;t like them to show.&lt;/p&gt;
&lt;p&gt;I think there is an architectural way to solve this problem:&lt;br /&gt;
   a. explicitly restrict some photos on Faji side (make them private, so that external party like Beepa can&amp;#8217;t fetch them).&lt;br /&gt;
   b. when granting authorization on Faji side choose which photos to share.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/GVJ0wsyMS8I" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042" href="http://hueniverse.com/oauth/guide/workflow/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37681</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by craig</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/ca4PAVwbBlc/" type="text/html" />

		<author>
			<name>craig</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37620</id>
		<updated>2012-01-25T19:11:51Z</updated>
		<published>2012-01-25T19:11:51Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37620">&lt;p&gt;fantastic &amp;#8211; I appreciated that you took the time to explain concepts like hashing and utf-8 encoding along the way. Excellent article!&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/ca4PAVwbBlc" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37620</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/1S08E5JpdYk/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37611</id>
		<updated>2012-01-25T15:46:39Z</updated>
		<published>2012-01-25T15:46:39Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37611">&lt;p&gt;I&amp;#8217;m not familiar with Fanpage but if they provider an OAuth API to do this, you can register a client with them and perform normal OAuth authorization on your server then post to their status update.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/1S08E5JpdYk" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37571" href="http://hueniverse.com/questions/#comment-37571" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37611</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Marcel Gringo</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/j1wDrbnd7yo/" type="text/html" />

		<author>
			<name>Marcel Gringo</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37571</id>
		<updated>2012-01-24T09:44:11Z</updated>
		<published>2012-01-24T09:44:11Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37571">&lt;p&gt;Hi &amp;#8230; Question:&lt;/p&gt;
&lt;p&gt;I want to make an App on a Fanpage where people can write there experience on a  service. when published &amp;#8230; this experience is also posted on there own timeline as their status update &amp;#8230;&lt;/p&gt;
&lt;p&gt;Is this possible with OAuth ?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/j1wDrbnd7yo" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37571</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/3Ofxvn4Bu3Y/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37566</id>
		<updated>2012-01-24T06:40:40Z</updated>
		<published>2012-01-24T06:40:40Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37566">&lt;p&gt;Not sure.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/3Ofxvn4Bu3Y" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526#comment-37555" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37566</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/PUbo75tMqRk/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37565</id>
		<updated>2012-01-24T06:40:26Z</updated>
		<published>2012-01-24T06:40:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37565">&lt;p&gt;Plan, yeah. In practice, the app source needs some cleaning up so it is a question of when I get around to it.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/PUbo75tMqRk" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526#comment-37554" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37565</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/95NKNedrr_Q/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37564</id>
		<updated>2012-01-24T06:39:34Z</updated>
		<published>2012-01-24T06:39:34Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37564">&lt;p&gt;That depends on how the client chooses to implement it. They can keep the access token and look it up using a session cookie. Also, the provider can also automatically redirect back without prompting the user to do it again.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/95NKNedrr_Q" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042#comment-37507" href="http://hueniverse.com/oauth/guide/workflow/#comment-37507" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37564</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Ron Heiney</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/b7ICq4e4d5k/" type="text/html" />

		<author>
			<name>Ron Heiney</name>
			
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37555</id>
		<updated>2012-01-23T17:01:33Z</updated>
		<published>2012-01-23T17:01:33Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555">&lt;p&gt;Does the Facebook authentication work with localhost:8000, I was able to log in with twitter.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/b7ICq4e4d5k" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37555</feedburner:origLink></entry>
	<entry>
		<title>Comment on Sled, Yahoo!, and Moving On by Ron Heiney</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/zEjlwhUXtDs/" type="text/html" />

		<author>
			<name>Ron Heiney</name>
			
		</author>

		<id>http://hueniverse.com/?p=1526#comment-37554</id>
		<updated>2012-01-23T15:45:08Z</updated>
		<published>2012-01-23T15:45:08Z</published>
		<content type="html" xml:base="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554">&lt;p&gt;&amp;#8220;including the soon to be open sourced iPhone app we never got to release&amp;#8221; Is the plan to still release the mobile app?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/zEjlwhUXtDs" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?p=1526" href="http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/2011/12/sled-yahoo-and-moving-on/#comment-37554</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by Okeke Emmanuel</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/z1ygXstBKps/" type="text/html" />

		<author>
			<name>Okeke Emmanuel</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37552</id>
		<updated>2012-01-23T11:57:25Z</updated>
		<published>2012-01-23T11:57:25Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37552">&lt;p&gt;Many thanks.&lt;br /&gt;
I believe this will help me on something i&amp;#8217;m currently working on. &lt;img src='http://hueniverse.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /&gt; &lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/z1ygXstBKps" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37552</feedburner:origLink></entry>
	<entry>
		<title>Comment on Protocol Workflow by Eddie</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/9pXlsInLplc/" type="text/html" />

		<author>
			<name>Eddie</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1042#comment-37507</id>
		<updated>2012-01-21T09:09:03Z</updated>
		<published>2012-01-21T09:09:03Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/workflow/#comment-37507">&lt;p&gt;Great demostration. But what happens if she revisits Beppa again? Does she have to go through the same process?&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/9pXlsInLplc" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1042" href="http://hueniverse.com/oauth/guide/workflow/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/workflow/#comment-37507</feedburner:origLink></entry>
	<entry>
		<title>Comment on Authentication by paul</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/8M7gDwEaTRI/" type="text/html" />

		<author>
			<name>paul</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1051#comment-37490</id>
		<updated>2012-01-20T15:14:52Z</updated>
		<published>2012-01-20T15:14:52Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/authentication/#comment-37490">&lt;p&gt;thanks for taking the time to write this article. i had to read some of twiters oauth stuff to get to a point where i understood this article, but that just shows how concise it was. thank you.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/8M7gDwEaTRI" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1051" href="http://hueniverse.com/oauth/guide/authentication/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/authentication/#comment-37490</feedburner:origLink></entry>
	<entry>
		<title>Comment on Introduction by Dhaval</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/tEZz6AzAOFE/" type="text/html" />

		<author>
			<name>Dhaval</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1027#comment-37458</id>
		<updated>2012-01-19T11:10:34Z</updated>
		<published>2012-01-19T11:10:34Z</published>
		<content type="html" xml:base="http://hueniverse.com/oauth/guide/intro/#comment-37458">&lt;p&gt;Best example of &amp;#8220;Luxury Car&amp;#8217;s Valet key&amp;#8221;&lt;br /&gt;
short and easy to understand primary thing of OAuth.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/tEZz6AzAOFE" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1027" href="http://hueniverse.com/oauth/guide/intro/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/oauth/guide/intro/#comment-37458</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/VJDvaafL8Ok/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37356</id>
		<updated>2012-01-13T16:11:10Z</updated>
		<published>2012-01-13T16:11:10Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37356">&lt;p&gt;These decisions are all part of the provider&amp;#8217;s architecture and all options mentioned are perfectly valid. I would optimize the user experience to make the most sense.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/VJDvaafL8Ok" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37313" href="http://hueniverse.com/questions/#comment-37313" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37356</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/4oqk6zJW22w/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37355</id>
		<updated>2012-01-13T16:09:26Z</updated>
		<published>2012-01-13T16:09:26Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37355">&lt;p&gt;Sorry but I am unable to assist with any particular vendor. You should reach out to Yahoo! for support.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/4oqk6zJW22w" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37315" href="http://hueniverse.com/questions/#comment-37315" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37355</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by Eran Hammer</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/atV311FwyD0/" type="text/html" />

		<author>
			<name>Eran Hammer</name>
			<uri>http://hueniverse.com</uri>
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37354</id>
		<updated>2012-01-13T16:08:52Z</updated>
		<published>2012-01-13T16:08:52Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37354">&lt;p&gt;Sorry but I am unable to assist with any particular vendor. You should reach out to them for support.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/atV311FwyD0" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183#comment-37296" href="http://hueniverse.com/questions/#comment-37296" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37354</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by liby mathew</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/HSJwPXjLgOM/" type="text/html" />

		<author>
			<name>liby mathew</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37315</id>
		<updated>2012-01-12T03:57:53Z</updated>
		<published>2012-01-12T03:57:53Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37315">&lt;p&gt;I am trying to access Yahoo&amp;#8217;s contact API and I&amp;#8217;m not able to get request token by giving URI request using my consumer key and secret.It is showing &amp;#8220;file not found&amp;#8221; while giving request.&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/HSJwPXjLgOM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37315</feedburner:origLink></entry>
	<entry>
		<title>Comment on Got Questions? by tony kerz</title>
		<link rel="alternate" href="http://feedproxy.google.com/~r/Hueniverse-Comments/~3/0m5IQTiscwM/" type="text/html" />

		<author>
			<name>tony kerz</name>
			
		</author>

		<id>http://hueniverse.com/?page_id=1183#comment-37313</id>
		<updated>2012-01-12T02:59:58Z</updated>
		<published>2012-01-12T02:59:58Z</published>
		<content type="html" xml:base="http://hueniverse.com/questions/#comment-37313">&lt;p&gt;hi eran, &lt;/p&gt;
&lt;p&gt;congrats on your new job and good luck @ walmart!&lt;/p&gt;
&lt;p&gt;i&amp;#8217;m working on a project where we are trying to use oauth (2) for authentication (click this button to sign in using your &amp;#8216;xyz-oauth-provider&amp;#8217; account). &lt;/p&gt;
&lt;p&gt;in this use-case, the client (user) enacts the oauth handshake with the provider, is prompted to login to the provider, is prompted to grant access to some scope of provider resources, and if all goes well, the client successfully gets an access token and uses it to call an api at the provider to get some basic account information which it uses to set up a local session. &lt;/p&gt;
&lt;p&gt;when the client&amp;#8217;s local session is complete it &amp;#8216;goes away&amp;#8217; meaning it tosses the access token. &lt;/p&gt;
&lt;p&gt;when the same user comes back (say the next day after the session with the provider has expired) via the client to run through the same process again, they are prompted to login to the provider again, but they are also prompted to grant access again. &lt;/p&gt;
&lt;p&gt;my initial instinct is that the provider should *not* prompt the user to grant access again (and let&amp;#8217;s just simplify the question for now by saying that the initial grant should have no expiration so that the refresh flow isn&amp;#8217;t in play). &lt;/p&gt;
&lt;p&gt;ok, so that is the setup for my question which is: &lt;/p&gt;
&lt;p&gt;does the spec cover this situation in terms of specifying how a provider should behave in this case? &lt;/p&gt;
&lt;p&gt;i.e. is it the client&amp;#8217;s responsibility to hold onto an access token and not ask for one twice (in which case i&amp;#8217;m unclear how to do repetitive sign-on&amp;#8217;s using oauth),&lt;br /&gt;
*or* is it the provider&amp;#8217;s responsibility to not prompt the same user if they have already granted access (and possibly return the same access token that they were initially issued). &lt;/p&gt;
&lt;p&gt;i hope my questions are relatively clear, but i&amp;#8217;d be happy to clarify if not. &lt;/p&gt;
&lt;p&gt;thanks! tony&amp;#8230;&lt;/p&gt;
&lt;img src="http://feeds.feedburner.com/~r/Hueniverse-Comments/~4/0m5IQTiscwM" height="1" width="1"/&gt;</content>
		<thr:in-reply-to ref="http://hueniverse.com/?page_id=1183" href="http://hueniverse.com/questions/" type="text/html" />
	<feedburner:origLink>http://hueniverse.com/questions/#comment-37313</feedburner:origLink></entry>
</feed>

