An ingredient of Privacy-Protected logins or payments.This add-on checks each page to have "A" tags or "INPUT hidden" tags having "pp-authorizer" class and prompts to move to their links. Using in the middle of OAuth makes it more secure.
There is a problem about anonymous authentication.
By allowing authentication providers to authenticate other Internet shops or bulletin board sites, it is possible to reduce the privacy information that Internet shops or bulletin board sites must keep. It is an advantage that users can use Internet stores or bulletin boards even with lower reliability. This can realize "anonymous login (privacy protected login)" or "anonymous payment (privacy protected payment)".
At this time, processing needs to flow from the bulletin board etc. to the authentication provider, but there is a danger of impersonation in redirecting from a site that must be less reliable to a more reliable site.
In order to prevent this impersonation, protocol should not permit automatic redirection from a site of lower reliability to a site of higher reliability, and if the site of lower reliability desires manual redirection, a message that indicates that effect should be displayed on the page, and the remaining necessity is only to have a bookmarklet or add-on that follows the link after checking that the link included in the page is correct.
Such an add-on is this PP Authorizer.
(However, there will be no page that supports the PP Authorizer for the time being. Then what should we do? You can use the PP Interrupter Lite which realizes similar operation in a point that you have to click on an icon in the address bar before authentication.)
The author of this add-on wishes that such functions are installed as standard on browsers, and that all sites stop the automatic redirection as described above. This add-on includes Twitter and Hatena as authentication providers from the beginning, and other authorities ... such as bank associations ... can donate much donations to browser developers so that their authentication provider information will be included from the beginning. The author is dreaming that browser developers acquire abundant development funds thereby.
このアドオンは "A" タグや "INPUT hidden" タグで "pp-authorizer" クラスを持つものをチェックし、そのタグが示すリンクに遷移するよう促す。例えば OAuth の途中でこれを使うとよりセキュアになると私は考える。