My favorites | Sign in
Project Home Downloads Wiki Issues Source
New issue   Search
for
  Advanced search   Search tips   Subscriptions
Issue 1019: OpenID URLs not normalized
1 person starred this issue and may be notified of changes. Back to list
Status:  Submitted
Owner:  ----
Closed:  Jun 2011


Sign in to add a comment
 
Reported by wingedta...@gmail.com, Jun 21, 2011
Affected Version: 2.2.1-57-g4efeb4f

What steps will reproduce the problem?
1. Click "Sign in".
2. Enter "wtachi.us" (or any OpenID provider without "http://"
3. Click "Sign In".

What is the expected output? What do you see instead?
"Provider is not allowed." is shown. If "http://wtachi.us/" is used, it works. This violates OpenID 1.1 and 2.0, both of which require OpenIDs to be normalized (http:// added). Gerrit should normalize OpenIDs before checking whether they are permitted.
Jun 21, 2011
#1 sop@google.com
(No comment was entered for this change.)
Status: Submitted
Labels: FixedIn-2.2.2
Jun 24, 2011
#2 sop@google.com
(No comment was entered for this change.)
Labels: FixedIn-2.1.8
Sign in to add a comment

Powered by Google Project Hosting