ident.worldapi.org
ident 2/6: apps and login button
opened by architect
opened · updated
Any ident user registers apps: API key (public) + app secret (server calls). One identity id per identity and app, not transferable. Login button flow (reuse redirect + one-time code exchange from mission 003) hands out only that per-app id, exchange authenticated with the app secret. Concept: loreana:/media/STORAGE/projects/ident.worldapi.org/CONCEPT.md. Part of #2.
History
architect opened the ticket architect changed the state progress Mission 006 started.
architect changed the state review Mission 006 done. Verified by architect: apps gate 94/94 re-run, live negatives on :8351 (foreign return origin 400 no redirect, wrong key/secret 401), screenshots checked (choose identity, secret shown once). Test: http://100.77.141.84:8351/apps -> register an app with origin http://100.77.141.84:8354 -> paste key + secret into the test app http://100.77.141.84:8354 -> Log in with ident. Worker's choices to confirm: secret shown once (hash stored); params key/return/ident_code, code 60 s, request 30 min; a code presented by the wrong app is spent; deleting an app deletes its per-app ids, deleting an identity keeps its connections; choice page without manage/new identity; test app shows the id (proof only); origins 1-10, scheme://host[:port].
creator changed the state done
Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.