ident.worldapi.org
Harden app login before going public
opened by architect
opened · updated
From mission 003 review. Before ident is reachable publicly: (1) each app gets a secret; /api/exchange requires it and checks that the code was issued for that app and return origin. (2) Test real mail via mail.byrod.in (SMTP path is wired, untested); a bounce must reach the browser, not only the log. (3) Expiry for the pending verified email on the session. (4) Sign out for apps / sign out everywhere.
Children
2 of 3 children done
done ident.worldapi.org #16Question: how long should an ident login last?open ident.worldapi.org #17Question: delete old sessions at once on 'sign out everywhere'?done ident.worldapi.org #18Question: what did 'expiry for the pending email' mean?
History
architect opened the ticket architect commented Status 2026-09-24: done - (1) app secret + exchange bound to the app (ident 2/6); (2) real mail via mail.byrod.in (works on Byrodin since the TLS image fix); per-IP limit on code requests (mission 010). Still open - (3) expiry for the pending verified email on the session; (4) sign out for apps / sign out everywhere; session cookie without Secure flag (hybriel#27).
Architect changed the state progress A worker started on this ticket.
colony-lease: s-20260924T1527-525807 · host Loreana · started · ms 1790270825779
Architect changed the state open Back to open: the worker stopped without a usable result (it ran out of steps) — the next worker tries again.
colony-run: s-20260924T1527-525807 · host Loreana · no report
Architect commented The first worker ran out of steps just before reporting — its work is kept and will be rescued.
Architect commented Half done: the changes are built and tested in a work copy, but not yet in the app.
Details:
- the next worker continues from there
- still to do: copy into the app, finish one test file, update the docs
Architect changed the state progress A worker started on this ticket.
colony-lease: s-20260924T1637-e45613 · host Loreana · started · ms 1790275047006
Architect commented Session expiry and sign-out-everywhere / sign-out-per-app are now live in the project (ticket items 3+4); test bug fixed, full suite green.
Test: 1) sign in on ident, look at the account bar on / — a new 'Sign out everywhere' button appears next to 'Sign out' 2) click it, confirm — you are signed out and can sign in again right away 3) open an app's per-app page from /inbox — a 'Sign out of this app' button appears; clicking it makes the app forget you (a later login gets a new id) 4) leave a session idle past IDENT_SESSION_TTL_MS (default 14 days) — it stops working on its own, without touching other devices
- Questions for you: ident.worldapi.org #16, ident.worldapi.org #17, ident.worldapi.org #18
- Not done: Item 2 (real mail via mail.byrod.in) was already reported done by the architect on 2026-0… (and 3 more)
colony-report: s-20260924T1637-e45613 · sha256 5b09cf99dc59 · controller pass
Architect changed the state review Ready for you to test — see the last comment.
Architect commented Now live on ident.worldapi.org.
Test:
- Sign in at https://ident.worldapi.org — next to 'Sign out' there is 'Sign out everywhere'.
- Click it — you are signed out on every device.
- In /inbox open an app — 'Sign out of this app' is there.
Caramboleyo changed the state done
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.