How to revoke OpenID access authorizations?

Asked by Jeff Fortin Tam

There doesn't seem to be a place anywhere in login.launchpad.net or launchpad.net/~my-username to revoke access to third parties that have requested auth through launchpad's openid...

Question information

Language:
English Edit question
Status:
Answered
For:
Canonical SSO provider Edit question
Assignee:
No assignee Edit question
Last query:
Last reply:
Revision history for this message
Stuart Metcalfe (stuartmetcalfe) said :
#1

Which 3rd parties' access do you want to revoke? And why (if you don't mind me asking)?

Revision history for this message
Jeff Fortin Tam (kiddo) said :
#2

I don't have any right now, but the fact that there doesn't seem to be a feature to do so seems like a security problem to me and makes me nervous about using launchpad as an openID provider. Others seem to provide such a way to revoke authorizations from a central place.

Example:
https://www.google.com/accounts/IssuedAuthSubTokens?service=profiles

Revision history for this message
ISD Branch Mangler (isd-branches-mangler) said :
#3

Those other services (including the one you've pointed to) are using OAuth, not OpenID. With OpenID there's not need for that because each time you log into the service the server needs to contact the OpenID provider to authenticate the access.

As for revoking OAuth tokens, you can do that from your https://login.ubuntu.com/+applications page.

Revision history for this message
Stuart Metcalfe (stuartmetcalfe) said :
#4

The only time the ability to revoke access is needed in OpenID is if the provider provides auto-authorisation functionality so that you don't get prompted every time you want to log in to a site. Ubuntu SSO doesn't currently support that so what you're asking for isn't needed yet. When we do bug #600583 ("Enable user-controlled auto-login"), the ability to revoke auto-authorisation per-site will be added (see the bug's description for more details).

Can you help with this problem?

Provide an answer of your own, or ask Jeff Fortin Tam for more information if necessary.

To post a message you must log in.