{"id":1168,"date":"2010-12-28T19:24:11","date_gmt":"2010-12-28T18:24:11","guid":{"rendered":"http:\/\/t-machine.org\/?p=1168"},"modified":"2010-12-28T19:24:11","modified_gmt":"2010-12-28T18:24:11","slug":"dont-use-bitbucket-broken-openid-authentication","status":"publish","type":"post","link":"http:\/\/new.t-machine.org\/index.php\/2010\/12\/28\/dont-use-bitbucket-broken-openid-authentication\/","title":{"rendered":"Don&#8217;t use BitBucket &#8211; broken OpenID authentication"},"content":{"rendered":"<p>We&#8217;re starting a new client project, and the client uses Mercurial exclusively, all through BitBucket.<\/p>\n<p><a href=\"https:\/\/t-machine.org\/wp-content\/uploads\/Screen-shot-2010-12-28-at-18.16.42.png\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/t-machine.org\/wp-content\/uploads\/Screen-shot-2010-12-28-at-18.16.42.png\" alt=\"\" title=\"Screen shot 2010-12-28 at 18.16.42\" width=\"363\" height=\"66\" class=\"aligncenter size-full wp-image-1169\" srcset=\"https:\/\/t-machine.org\/wp-content\/uploads\/Screen-shot-2010-12-28-at-18.16.42.png 363w, https:\/\/t-machine.org\/wp-content\/uploads\/Screen-shot-2010-12-28-at-18.16.42-150x27.png 150w, https:\/\/t-machine.org\/wp-content\/uploads\/Screen-shot-2010-12-28-at-18.16.42-300x54.png 300w\" sizes=\"(max-width: 363px) 100vw, 363px\" \/><\/a><\/p>\n<p>BitBucket has a stupid user-accounts system, that demands you invent a globally-unique username. Oh dear lord &#8211; how amateurish are you guys?<\/p>\n<p>Aha! BUT! &#8230; they have a (very subtle) link to let you use OpenID instead. Phew! My day is saved &#8211; I don&#8217;t have to be &#8220;dodgy-69-sucker-11111&#8221; just in a desperate attempt to work around a naive website architect.<\/p>\n<h4>OpenID FAIL<\/h4>\n<p>Except &#8230; once you&#8217;ve sacrificed your private account details to Atlassian, they &#8230; don&#8217;t allow you to login. It reports &#8220;success&#8221; but tells you that you&#8217;re not allowed to use OpenID to access the site, you STILL have to create a non-OpenID account, using a globally unique ID.<\/p>\n<p>I&#8217;m sure they&#8217;re doing &#8220;something&#8221; with OpenID, but I get the impression that the folks at BitBucket don&#8217;t grok what most of the world is using it for&#8230;<\/p>\n<h4>How do I take back my Identity, you fraudsters?<\/h4>\n<p>Well, Atlassian won&#8217;t help you there.<\/p>\n<p>Fortunately, Google did&#8230;<\/p>\n<h4>Google&#8217;s UI designers FTW<\/h4>\n<p>I used Google as my OpenID source this time around. And, *fortunately*, Google&#8217;s process for de-authorizing a website is very simple.<\/p>\n<p>I usually assume Google&#8217;s UI is great, and I usually only blog about it when it fails badly, but here&#8217;s an example where it works beautifully.<\/p>\n<p>(hint: there&#8217;s a shortcut &#8211; but Google might change the link in future. You can go directly to: <a href=\"https:\/\/www.google.com\/accounts\/IssuedAuthSubTokens\">https:\/\/www.google.com\/accounts\/IssuedAuthSubTokens<\/a>)<\/p>\n<p>Just go to your account page (<a href=\"https:\/\/www.google.com\/accounts\/\">https:\/\/www.google.com\/accounts\/<\/a>), and *right at the top of the page* (thanks, Google!) is a link to all your authorized websites &#8211; it&#8217;s in a big white space on it&#8217;s own, VERY easy to find.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;re starting a new client project, and the client uses Mercurial exclusively, all through BitBucket. BitBucket has a stupid user-accounts system, that demands you invent a globally-unique username. Oh dear lord &#8211; how amateurish are you guys? Aha! BUT! &#8230; they have a (very subtle) link to let you use OpenID instead. Phew! My day [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45,46,32],"tags":[],"_links":{"self":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/1168"}],"collection":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/comments?post=1168"}],"version-history":[{"count":0,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/posts\/1168\/revisions"}],"wp:attachment":[{"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/media?parent=1168"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/categories?post=1168"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/new.t-machine.org\/index.php\/wp-json\/wp\/v2\/tags?post=1168"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}