MicroID on profile pages
MicroID on profile pages
| Issue ID: | 10 |
| Issue Category: | bug |
| Component: | uncategorized |
| Priority: | critical |
| Status: | fixed |
| Assigned: | Unassigned |
| Version: | 0.5 |
| Milestone: | 0.9 |
We should output [[http://microid.org/ | MicroID]]s for user pages. There should be a setting in the profile section to turn this off, but it should be on by default.
-> Patch here: http://identi.ca/notice/123335 -- mikenz
-> I have a number of issues with the current implementation:
-> 1. in the current profile microID defaults to "on" for both email address and XMPP - default should be off
-> 2. while providing a microID is a nice idea, it SHOULD NOT be tied '''automatically''' to either email address or jabber address: neither of these are necessarily stable (they are not for me) and changing then would necessitate to re-claim your profile URL. I'm on my third jabber address already (2nd for identi.ca) because servers may simply stop working; when I go traveling, I'd change my contact email for identi.ca for one that I can access securely while traveling. The microID spec allows using '''any''' two URIs; teh user's URI does not have to be an email or jabber address.
-> I think it should work as follows:
-> 1. on the '''main''' profile page provide a checkbox to turn on/off generating a microID plus a textbox to provide a URI that you control
-> 2. URI could be email, jabber, URL; for a URL an openID URL could be used. In any case a URI controlled by and provided by the user ''independent'' of what the current email and/or jabber address used for identi.ca happens to be
-> 3. that way, a URL can be "claimed" and be stable even when email and jabber addresses change
->[[~Marjolein Katsma]]

Updates
#1
I'm going to start a new bug for adding a MicroID for each OpenID.
#2
Oh, and: I disagree pretty much with all of Marjolein's concerns.
1) MicroID is more than safe enough to have on by default. It's possible to turn it off; that's good enough for the rare political dissident who needs to dissociate themselves from an account.
2) The use case for not using the URIs that the user already provided for us is weak. I don't want to add an additional layer of complexity for verifying arbitrary URLs. We already have a way of confirming your identity for your OpenID, for your email address, and for Jabber. I don't think we need to get more complicated than that.
You can also subscribe to the
RSS feed for updates to this issue.