Django-SocialAuth - Login via twitter, facebook, google, etc. from single app
uswaretech.com
uswaretech.com
For users it's not clear which site is legit.
This is legit: hxxps://www.google.com/accounts/ServiceLogin?service=lso&domain=Socialauth.uswaretech.net&anonSign=1&continue=https%3A%2F%2Fwww.google.com%2Faccounts%2Fo8%2Fud%3Fst%3DBDKB7DbZLrOEjmE3c2kS
This is not: hxxps://www.google.com.evilsite.com/accounts/ServiceLogin?service=lso&domain=Socialauth.uswaretech.net&anonSign=1&continue=https%3A%2F%2Fwww.google.com%2Faccounts%2Fo8%2Fud%3Fst%3DBDKB7DbZLrOEjmE3c2kS
For the avarage user, logging in means, click on the bookmark, see if a loginform pops up, log in. Now it's go to random site, get asked for your gmail password, and type it or else 'no cookie for you'.
That being said, I have no solution for the problem.
Most of the time, since you are already logged-in on Facebook google, yahoo or twitter, you will not be prompted for password, only for approval of authentication.
I've spotted another weakness though on the facebook login. The username's are generated as facebook_$firstname, which will lead to duplicates on big sites quite fast. I'd like to see a mechanism asking the users to chose a username.
One way to look at it is: stupid user, you did it to yourself.
Another is: lots of people will be fooled, maybe we should rethink.
As I've said before, I have no solid solution.
It doesn't have the facebook or twitter, but it does work well with most openid providers (google, yahoo, etc). Plus, it lets users go ahead and just create a normal login if they don't want to use openid.
There's an example at openid-example.e-engura.org if you're interested.
That said, I'm sure lots of other Rails developers have already built their own solution. I'm also sure some are more mature than mine (i.e. in production). Isn't uservoice.com backed by Rails? Their social authentication is so pretty Google uses it as a demo.