6 ms·
You're exactly right stickfigure. * You have to make sure the attributes are properly signed by the OpenID provider which is what the security advisories by Go
by mikesun 14y ago
You're exactly right stickfigure.
* You have to make sure the attributes are properly signed by the OpenID provider which is what the security advisories by Google and OpenID foundation were about.
* You can't trust any OpenID provider to give you a correct and verified email address. For the specific case of Google single sign-on, you can trust the Google OpenID provider.