what security aspects should be kept in mind while implementing openid from scratch(without using library).