Why would you do an automatic HTML post rather than a simple redirect?

Is this so developers can automatically generate a login form that posts directory to the remote server when the OpenID is known?

eg.

  1. User is not logged in and visits your login page.
  2. You detect the user's openID from a cookie.
  3. Form is generated that directly posts to remote OpenID server.
  4. Remote server redirects user back to website.
  5. Website logs in the user.

If this is the case I can see the benefit. However this assumes that you keep the user's openID in a cookie when they log out.

I can find very little information on how this spec should be best implemented.

See HTML FORM Redirection in the official specs:

http://openid.net/specs/openid-authentication-2_0.html#indirect_comm

I found this out from looking at the PHP OpenID Library (version 2.1.1).

// Redirect the user to the OpenID server for authentication.
// Store the token for this authentication so we can verify the
// response.

// For OpenID 1, send a redirect.  For OpenID 2, use a Javascript
// form to send a POST request to the server.
if ($auth_request->shouldSendRedirect()) {
    $redirect_url = $auth_request->redirectURL(getTrustRoot(),
                                               getReturnTo());

    // If the redirect URL can't be built, display an error
    // message.
    if (Auth_OpenID::isFailure($redirect_url)) {
        displayError("Could not redirect to server: " . $redirect_url->message);
    } else {
        // Send redirect.
        header("Location: ".$redirect_url);
    }
} else {
    // Generate form markup and render it.
    $form_id = 'openid_message';
    $form_html = $auth_request->htmlMarkup(getTrustRoo
Edit
Report