Re: [OAUTH-WG] register prefixes as opposed to full parameter names

Michael D Adams <mike@automattic.com> Wed, 07 July 2010 19:16 UTC

Return-Path: <michael.d.adams@gmail.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 3F3473A68BF for <oauth@core3.amsl.com>; Wed, 7 Jul 2010 12:16:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level:
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CmSCJXA69Hb3 for <oauth@core3.amsl.com>; Wed, 7 Jul 2010 12:15:59 -0700 (PDT)
Received: from mail-iw0-f172.google.com (mail-iw0-f172.google.com [209.85.214.172]) by core3.amsl.com (Postfix) with ESMTP id 645513A6909 for <oauth@ietf.org>; Wed, 7 Jul 2010 12:15:57 -0700 (PDT)
Received: by iwn38 with SMTP id 38so9777iwn.31 for <oauth@ietf.org>; Wed, 07 Jul 2010 12:16:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:mime-version:sender:received :in-reply-to:references:from:date:x-google-sender-auth:message-id :subject:to:cc:content-type; bh=cOzPJaBMxjX2lpchcopDBludH/+S0u0xChkm1HGn6zQ=; b=X/26EfeV5aIDMtOeh3/eRZLb30SxMc5poMd6dLC314/IOAvn8wEYjR4N8dh3McX0vF 8Pv4YHFIzBiqEmiDcSGV5cXh1SJpM5uLHuHq61b2XRAab6Kvr5jSvY9eHATBQ08oClSa FgR+Ynzcg9HuzE/AlkkRtsX2XAgDbUVeirGW0=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:sender:in-reply-to:references:from:date :x-google-sender-auth:message-id:subject:to:cc:content-type; b=gHGonz7Fzxgvp3Y7LSHSFW72g9C2Iw5IbkiQWHZp0DXO/UstTUunuFmucqWsl9eNex WDKb7Wm+0SmSW4lsmKDYtO7WRDNvOjQhKGM01oLElELTyqcOWm9GuHDByuzD7LSwKE9q rQtiulbVVtsrjVY+J64dtDxciXrNyBiBL9E58=
Received: by 10.231.174.136 with SMTP id t8mr7387892ibz.158.1278530158360; Wed, 07 Jul 2010 12:15:58 -0700 (PDT)
MIME-Version: 1.0
Sender: michael.d.adams@gmail.com
Received: by 10.231.179.143 with HTTP; Wed, 7 Jul 2010 12:15:38 -0700 (PDT)
In-Reply-To: <AANLkTiln5m_ZxSfp6Kt_1Za53E-902gFIHCko_Xj0RN_@mail.gmail.com>
References: <1278439815.2445.8.camel@localhost.localdomain> <C858C2B1.36C16%eran@hueniverse.com> <AANLkTimWZugW68Gkg_CCYZL8TUIbtaNEAlQS7cMTTSZV@mail.gmail.com> <AANLkTimsxRHsXggcEsQhgD04YgbdUlrm_rojSi_SLc-X@mail.gmail.com> <AANLkTikDx54ypvWMlZXGlgXsBi3wErcs3-SxO2hYVQYW@mail.gmail.com> <AANLkTinZTSR-ZIe2kZYYLVKDRkr68JEHP7vxtyOroHGa@mail.gmail.com> <AANLkTimY78I-0BC94XVSffwe-sS3HKamXzX39pj04JKE@mail.gmail.com> <AANLkTiln5m_ZxSfp6Kt_1Za53E-902gFIHCko_Xj0RN_@mail.gmail.com>
From: Michael D Adams <mike@automattic.com>
Date: Wed, 07 Jul 2010 12:15:38 -0700
X-Google-Sender-Auth: uQwI-idc0XYNU9LSuwi0Qvpbops
Message-ID: <AANLkTimMqqhHuF9yT3fpE2uuhS69nTJjJqQPvGvPiKt6@mail.gmail.com>
To: Marius Scurtescu <mscurtescu@google.com>
Content-Type: text/plain; charset="ISO-8859-1"
Cc: OAuth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] register prefixes as opposed to full parameter names
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Jul 2010 19:16:00 -0000

On Wed, Jul 7, 2010 at 10:31 AM, Marius Scurtescu <mscurtescu@google.com> wrote:
> On Wed, Jul 7, 2010 at 1:10 AM, Michael D Adams <mike@automattic.com> wrote:
>> Actually, for a small minority of WordPress sites wanting to enable
>> OAuth (those not supporting so called "pretty permalinks"), the
>> WordPress plugin would need to internally reserve one query parameter
>> to get the ball rolling.  Theoretically, that need leads to the
>> possibility of conflict, but I'm not worried about it.
>
> As far as I can tell pretty permalinks also use mod_rewrite so the PHP
> code still sees the query parameter.

Yes.  The point is that the plugin can intercept the request early
enough that it doesn't matter.

There is a small chance for conflict, but the conflict is not inherent
to the core spec or to the spec of an extension, only to the
particular implementation of the plugin.  In the pretty permalink
case, the conflict can easily be addressed with a new release of the
plugin (developed, out the door, and pulled to all sites in a day)
without changing endpoints or otherwise breaking clients.  In the ugly
link case, you might need to change the endpoints' URLs.

Any "serious" site will be using pretty permalinks.

This situation seems acceptable to me.  With a new extension, you need
a new release of the plugin anyway (or the release of a plugin for the
plugin).  You're blocking deployment on development, which is always
true.

All of this to say: WordPress is flexible enough to implement the
current spec, and I predict that WordPress is flexible enough to
implement the final spec.  I believe no special consideration need be
given WordPress in the spec writing process.  If I see anything, I'll
raise the issue.

Mike
--mdawaffe