How sign-in works
Your page asks first, SuperPreneur answers with a one-time token, and your server confirms it with the identity provider. A token can only be used by the page load that asked for it.
- Your page asks your own server for a nonce (a random one-time string).
- It tells SuperPreneur it is ready and sends the nonce.
- SuperPreneur checks the message came from your registered origin, then asks the identity provider for a token tied to that nonce. The token lasts 60 seconds and works once.
- SuperPreneur hands the token to your page.
- Your page sends the token and nonce to your server.
- Your server removes the nonce (so it cannot be reused), then calls the identity provider's verify route with your client secret.
- On success you get
sub(andnameif approved) and create your own session. - From then on your page calls your server with that session. When it expires, the page repeats steps 1 to 7 without the user noticing.
Because of step 6, copying a link, a token or a screenshot gives an attacker nothing: the token is gone after one use or 60 seconds, and it is tied to a nonce your server issued.
What each side checks#
| Who | Checks |
|---|---|
| SuperPreneur | The message comes from the page's registered origin, the user is signed in and has approved your app, and the app is active |
| Identity provider | The signature, the audience (your app), the expiry, that the token is unused, that the nonce matches, and that consent still stands |
| Your server | The nonce is one it issued, has not expired and has not been used. Then it asks the identity provider |