ticketsLog in with ident

ident.worldapi.org #2formerly #22

Harden app login before going public

done

opened by architect

opened · updated

From mission 003 review. Before ident is reachable publicly: (1) each app gets a secret; /api/exchange requires it and checks that the code was issued for that app and return origin. (2) Test real mail via mail.byrod.in (SMTP path is wired, untested); a bounce must reach the browser, not only the log. (3) Expiry for the pending verified email on the session. (4) Sign out for apps / sign out everywhere.

Children

2 of 3 children done

History

  1. architect opened the ticket
  2. architect commented

    Status 2026-09-24: done - (1) app secret + exchange bound to the app (ident 2/6); (2) real mail via mail.byrod.in (works on Byrodin since the TLS image fix); per-IP limit on code requests (mission 010). Still open - (3) expiry for the pending verified email on the session; (4) sign out for apps / sign out everywhere; session cookie without Secure flag (hybriel#27).

  3. Architect changed the state progress

    A worker started on this ticket.

    colony-lease: s-20260924T1527-525807 · host Loreana · started · ms 1790270825779

  4. Architect changed the state open

    Back to open: the worker stopped without a usable result (it ran out of steps) — the next worker tries again.

    colony-run: s-20260924T1527-525807 · host Loreana · no report

  5. Architect commented

    The first worker ran out of steps just before reporting — its work is kept and will be rescued.

  6. Architect commented

    Half done: the changes are built and tested in a work copy, but not yet in the app.

    Details:

    • the next worker continues from there
    • still to do: copy into the app, finish one test file, update the docs
  7. Architect changed the state progress

    A worker started on this ticket.

    colony-lease: s-20260924T1637-e45613 · host Loreana · started · ms 1790275047006

  8. Architect commented

    Session expiry and sign-out-everywhere / sign-out-per-app are now live in the project (ticket items 3+4); test bug fixed, full suite green.

    Test: 1) sign in on ident, look at the account bar on / — a new 'Sign out everywhere' button appears next to 'Sign out' 2) click it, confirm — you are signed out and can sign in again right away 3) open an app's per-app page from /inbox — a 'Sign out of this app' button appears; clicking it makes the app forget you (a later login gets a new id) 4) leave a session idle past IDENT_SESSION_TTL_MS (default 14 days) — it stops working on its own, without touching other devices

    colony-report: s-20260924T1637-e45613 · sha256 5b09cf99dc59 · controller pass

  9. Architect changed the state review

    Ready for you to test — see the last comment.

  10. Architect commented

    Now live on ident.worldapi.org.

    Test:

    1. Sign in at https://ident.worldapi.org — next to 'Sign out' there is 'Sign out everywhere'.
    2. Click it — you are signed out on every device.
    3. In /inbox open an app — 'Sign out of this app' is there.
  11. Caramboleyo changed the state done

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.