Yadisã¨OpenIDã®é¢ä¿ (2) - Yadisãããã³ã«
d:id:ZIGOROu:20080214:1203011300ã®ç¶ãã§ãã
Yadisãããã³ã«ãç¥ãã
Yadis 1.0 (HTML) - The Yadis Protocolãããã¹ãã§ãããä»æ§ãªã®ã§å¤å°åé·ãªã®ã§è¦ç¹ã ãæãã¦ããã¾ãããã
ä½ã®ããã«Yadisãããã³ã«ãããã®ã
Relying Partyãããã®ã¦ã¼ã¶ã¼ã®Yadis IDã§ä½¿ãããµã¼ãã¹ãè¨è¿°ããYadis Resource Discriptorãå¾ãçºã«ããã¾ãã
ãã£ã¨åã¿ç ãã¦è¨ãã°ãã®ã¦ã¼ã¶ã¼ã®Yadisææ¸ãã©ãã«ããã®ãã調ã¹ãçºã®æç¶ãã§ãã
ä½æ Yadis Resource Descriptorãå¿ è¦ãªã®ã
ä¸ããããYadis ID(ãããURLãªãYadis URL)ã§ä½¿ããèªè¨¼ãµã¼ãã¹ãã©ããªã®ããRPãç¥ãçºã«ããã¾ããããã§è¨ãèªè¨¼ãµã¼ãã¹ã¯OpenIDã ã£ããLIDã ã£ããSAMLã ã£ãããã¾ãã
ã§ãããããYadis Resource Descriptorã£ã¦ã®ã¯ã»ã¨ãã©Yadisææ¸(XRDSææ¸)ã¨åãæå³ã§ãã(d:id:ZIGOROu:20080214:1203011300 ãåç
§)
ãã®Yadisææ¸ã«ããã®ã¦ã¼ã¶ã¼ã®èªè¨¼ãè¡ãããµã¼ãã¹ãè¤æ°è¨è¿°åºæ¥ãããèªè¨¼ä»¥å¤ã«ãIDãã¼ã¹ã§ä½¿ãããµã¼ãã¹(ä¾ãã°ãããã£ã¼ã«å±æ§äº¤æã¨ã)ãããã°ãããè¨è¼åºæ¥ã¾ãã
Yadisãããã³ã«ã®æµã
ãã£ããè¨ãã°ä¸è¨ã®ããã«ãªãã¾ãã
- Yadis IDãã¦ã¼ã¶ã¼ãRPã«æãã¾ã
- RPã¯Yadis IDã§ç¤ºãããURLã«ã¢ã¯ã»ã¹ãã¾ã
ã§ããã®Yadis IDã«ã¢ã¯ã»ã¹ããã¡ã½ãã(GET/HEAD)ã§å¿ è¦ã«å¿ãã¦ãæ大2å追å ã®HTTPãªã¯ã¨ã¹ããè¡ãå¿ è¦ãããã¾ãã
æåã®ãªã¯ã¨ã¹ã
RPã¯ã¦ã¼ã¶ã¼ããä¸ããããYadis URLã«å®éã«ã¢ã¯ã»ã¹ãã¾ãã
GETã§ãHEADã§ãæ§ãã¾ããã
ãã®ã¨ãã®ã¬ã¹ãã³ã¹ã«ããªã¨ã¼ã·ã§ã³ããã£ã¦ã
- metaè¦ç´ ã§http-equivã使ã£ã¦x-xrds-locationãè¨å®ãã¦ããhtmlãè¿ã£ã¦æ¥ã
- x-xrds-locationã¬ã¹ãã³ã¹ããããå«ãã§ãã
- ã¬ã¹ãã³ã¹ãããã®ã¿ã§ãx-xrds-locationã¬ã¹ãã³ã¹ããããå«ãã§ãããcontent-typeãapplication/xrds+xmlã®å ´åããããã¯ä¸¡æ¹
- ææ¸ã®mimetypeãapplication/xrds+xmlã§ãããã®
ã«ãªãã¾ãã
ã§ãå ã ã®ç®çã¯Yadisææ¸ãå¾ãäºã ããæå¾ã®mimetypeãapplication/xrds+xmlã®å ´åã¯GETã§ã¢ã¯ã»ã¹ãã¦ãå ´åã¯ç®çãéãã¦ããã®ã§ãããã§çµäºã«ãªãã¾ãã
ãã以å¤ã®å ´åã¯ã
- x-xrds-locationãæå®ããã¦ããªããããã§æå®ããã¦ãURL
- content-typeãapplication/xrds+xmlã§HEADã§ã¢ã¯ã»ã¹ãã¦ãããã¬ã¹ãã³ã¹ããã£ãç¡ãå ´åã¯ä¸ããããYadis URL
ã«å¯¾ãã¦ããããå度GETãªã¯ã¨ã¹ããéãå¿ è¦ãããã¾ãã
ã¾ãæçµçã«application/xrds+xmlãªææ¸ã欲ãã訳ã§ããããAcceptãªã¯ã¨ã¹ããããã§application/xrds+xmlã追å æå®ãã¦ããã°ãYadisã®IdPã¯ããã解éãã¦ç´æ¥XRDSææ¸ãè¿ãã¦ãããããããã¾ããã*1
äºçªç®ã®ãªã¯ã¨ã¹ã
å
ã«æãã2ãã¿ã¼ã³ã®ãªã¯ã¨ã¹ããéãã±ã¼ã¹ãããã®ã§ãããå
ã
ã®ãªã¯ã¨ã¹ããHEADã§ãäºçªç®ã®ãªã¯ã¨ã¹ãã¯GETã«æããã ãã®å ´åã§ãx-xrds-locationã(ã¬ã¹ãã³ã¹ãããã¾ãã¯metaè¦ç´ ã§)æå®ããã¦ããå ´åã¯æ¹ãã¦ããã®URLã«GETã§ã¢ã¯ã»ã¹ããªããã°ãªããªãã
ãã®ãªã¯ã¨ã¹ãã3çªç®ã®ãªã¯ã¨ã¹ãã§ãã
ä¸çªç®ã®ãªã¯ã¨ã¹ã
ããã¯ããXRDSææ¸ã§ãããã¨ãä¿éããã¦ããã¯ããªã®ã§ããã®ãªã¯ã¨ã¹ãã«å¯¾ããã¬ã¹ãã³ã¹ãæ£ããXRDSææ¸ã§ãããªãã°ãæ£å¸¸ã«çµäºã¨è¨ãäºã«ãªãã¾ãã
ã©ããXRDSææ¸ã¾ãã¯XRDSææ¸ã®æå¨ã¨ãã¹ããã®åªå é ä½
- x-xrds-locationã¬ã¹ãã³ã¹ãããã§æå®ããã¦ãURL
- metaè¦ç´ ã§x-xrds-locationãæå®ããã¦ãå ´å
- ã¬ã¹ãã³ã¹æ¬æãapplication/xrds+xmlã®å ´å
ã®é çªã§ãã
OpenIDã¨Yadisãããã³ã«ã®é¢ãã
Yadis ID(Yadis URL)ã¯OpenIDã§è¨ãæã®Claimed Identifierã¨ä¸è´ããã±ã¼ã¹ãã»ã¨ãã©ã§ãããã
Claimed Identifierã§è¡¨ãããURL(ã¾ãã¯XRI)ã¯ãä½ããã®å½¢ã§XRDSææ¸ãè¿ãããã«ããæ¹ããOpenID Authentication 2.0ã§ã¯åªå
ããã¦ãããlinkè¦ç´ ã§OP EndPoint URLãæå®ããã®ã¯å°å¦çã¾ã§ãªè¨³ã§ãã
Claimed Identifierã ãããOP Identifierã ããããXRDSææ¸ãè¿ããæ¹ãäºææ§ã®é«ãå®è£
ã¨ãªãã¨æãã¾ãã
ã¾ãä»ã«ä½ã®ãµã¼ãã¹ã使ããããRPã«æããäºãåºæ¥ãã¨è¨ãç¹ã大ããã§ãã
linkè¦ç´ ãã¼ã¹ã®æ¢ç´¢ã ã¨èªè¨¼ãããçºã ãã®ç¨éã«ãªã£ã¦ãã¾ã訳ã§ããã
ã¾ã¨ã
Yadisãããã³ã«ãå®è£
ãããªãHEADã¯ä½¿ããªãæ¹ãè¯ãã¨æãã¾ãã
GETã§å§ãããã¢ã¯ã»ã¹ãã¦ãã°æ大2åã®ãªã¯ã¨ã¹ãã§æ¸ãããã§ãã
ã¾ãå®è£ ã«å½ãã£ã¦ã¯ã
- Acceptããããå¿ ãè¦ã¦ãapplication/xrds+xmlãæå®ããã¦ããã°åªå çã«XRDSææ¸ãè¿ãããã«ãã
- ããã§ãªããã°ã¬ã¹ãã³ã¹ãããã«x-xrds-locationãæå®ãã
ã®ã綺éºãªå®è£ ãªã®ããªã¨æãã¾ãã
次ã¯XRDSææ¸ã®ä¸èº«ãæ¸ãäºå®ã§ãã
*1:ã¨è¨ããIdPã¯ãããå®è£ ãã¹ãã§ããã