tst2005googlecode / step2

Automatically exported from code.google.com/p/step2
1 stars 0 forks source link

me.com domain is identified as OpenID provider #53

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
What steps will reproduce the problem?
1. go to http://www.puffypoodles.com/lso2 demo site
2. enter example@me.com
3. you will get a google login page 

What is the expected output? What do you see instead?

The page should not redirect to google page because me.com is not "really" 
registered with google apps. It seems some evil person tried to register it not 
the owner (Apple inc) and this causes issues to the users with me.com email 
address .

What version of the product are you using? On what operating system?

Mac osx 
Please provide any additional information below.

I think that the domain name me.com should be "verified" by google folks and 
forbidden to register as they did with yahoo, ebay , google etc ... to avoid 
such issues . 
  A better approach to fix the whole bug would be to do not "publish" the domain name in the  openid discovery service until the domain name ownership is  verified .

Original issue reported on code.google.com by mi...@epek.com on 4 Dec 2011 at 12:36