Closed (fixed)
Project:
OpenID
Version:
5.x-1.x-dev
Component:
OpenID Client
Priority:
Critical
Category:
Bug report
Assigned:
Unassigned
Reporter:
Created:
10 May 2007 at 21:13 UTC
Updated:
4 Jun 2007 at 21:24 UTC
The OpenID module currently sends a trust_root (or realm) value ending in an asterisk (in the path). For example, it sends "http://www.example.com/*". Wildcards are only valid in the authority section of the value. Wildcards in the path will cause return_to / realm checks to fail.
Comments
Comment #1
walkah commentedFixed in HEAD ... awaiting backport to 5.x
Comment #2
walkah commentedbackported.
Comment #3
(not verified) commented