Zoo

← back to the zoo

1. One sign-in, every app

Sign in once at account, and every app knows who you are without asking again.

The account shim: an app requires rc-auth.php and calls auth_user(). A signed-in browser is silently handed a token for that app; there is no sign-in page per app and no password anywhere.

This is the code serving the zoo right now: read from disk for this request, from commit 0c1c124a02 (live). The zoo's own self-check fetches this page and compares it byte for byte with the file it runs.

exhibits/01-one-sign-in.php sha256 93dae37dcc22 · raw

1<?php
2// Exhibit 1. The whole of sign-in, for any app, is two lines:
3//     require getenv("RC_LIB") . "/rc-auth.php";
4//     $me = auth_user();     // ["id", "username", "name", "picture"], or null for a visitor
5// The second app here is the sample `zoo-broken` (exhibit 8): its last good version shows the same card.
6return [
7    "n" => 1, "wing" => "Identity", "kind" => "human",
8    "title" => "One sign-in, every app",
9    "promise" => "Sign in once at account, and every app knows who you are without asking again.",
10    "block" => "The account shim: an app requires rc-auth.php and calls auth_user(). A signed-in browser is silently handed a token for that app; there is no sign-in page per app and no password anywhere.",
11    "show" => function (?array $me): string {
12        $second = rc_app_url("zoo-broken");
13        return '<p>Who am I, here on the zoo:</p>' . person($me)
14             . '<p>Now open <a href="' . h($second) . '/" target="_blank" rel="noopener">a second app on its own address</a>: it should show the same card, with no prompt.</p>'
15             . seen_button(1, $me, "Both cards showed me");
16    },
17];