1. One sign-in, every app
Sign in once at account, and every app knows who you are without asking again.
The account shim: an app requires rc-auth.php and calls auth_user(). A signed-in browser is silently handed a token for that app; there is no sign-in page per app and no password anywhere.
This is the code serving the zoo right now: read from disk for this request, from commit
77ff74344d (staging). The zoo's own self-check fetches this
page and compares it byte for byte with the file it runs.
exhibits/01-one-sign-in.php sha256 93dae37dcc22 · raw
1<?php 2// Exhibit 1. The whole of sign-in, for any app, is two lines: 3// require getenv("RC_LIB") . "/rc-auth.php"; 4// $me = auth_user(); // ["id", "username", "name", "picture"], or null for a visitor 5// The second app here is the sample `zoo-broken` (exhibit 8): its last good version shows the same card. 6return [ 7 "n" => 1, "wing" => "Identity", "kind" => "human", 8 "title" => "One sign-in, every app", 9 "promise" => "Sign in once at account, and every app knows who you are without asking again.", 10 "block" => "The account shim: an app requires rc-auth.php and calls auth_user(). A signed-in browser is silently handed a token for that app; there is no sign-in page per app and no password anywhere.", 11 "show" => function (?array $me): string { 12 $second = rc_app_url("zoo-broken"); 13 return '<p>Who am I, here on the zoo:</p>' . person($me) 14 . '<p>Now open <a href="' . h($second) . '/" target="_blank" rel="noopener">a second app on its own address</a>: it should show the same card, with no prompt.</p>' 15 . seen_button(1, $me, "Both cards showed me"); 16 }, 17];