ContentsThe library

Proving Who You Are

Borrowing Somebody Elses Proof

Last timeA Short One and a Long One

Signing in with another account means three parties, several redirects, and a short code exchanged for a token. Here is the exchange, with what each step proves and to whom.

The triangle

Everything so far had two parties: a person and a system. Delegated

sign-in has three, and most of the confusion about it comes from trying to

think about three parties with a two-party picture.

The person wants to use a site. The site wants to know who they are. A

third party, the authority, already knows them, because they have an

account there with a password and probably a second factor. The point of

the exercise is for the site to learn who the person is without ever

touching the proof.

Each edge of that triangle carries a different trust relationship. The

person trusts the authority with a password, and has done for years. The

site trusts the authority to make honest statements about people. The

authority trusts neither of the others and asks the person directly, in its

own window, whether this particular site may be told anything.

FIG 1Why the number of legs matters
time the person waits for the sign-in
number of redirects in the exchange
typical round trip latency
Four redirects at two hundred milliseconds is most of a second before anything is drawn, which is why the flow feels slow and why people are tempted to cut legs out of it. Every leg that gets cut removes a check, and the next section is what each one is for.

The exchange

Follow it once, slowly.

FIG 2One delegated sign-in
Thirteen steps for what the person experiences as one click. Trace the two things that travel through the browser, the request out and the code back, and notice that neither of them is worth stealing on its own. That is the design.
FIG 3The two legs, as they look on the wire
plaintext
leg one, through the browser
  GET /authorize
    client_id=site-1182
    redirect_uri=https://app.northwind.co/return
    response_type=code
    scope=openid profile email
    state=nTq8vK2wZ4
    code_challenge=hash of the secret verifier
    code_challenge_method=S256

  returns to https://app.northwind.co/return
    code=bb41c7d9
    state=nTq8vK2wZ4

leg two, site straight to authority
  POST /token
    grant_type=authorization_code
    code=bb41c7d9
    client_id=site-1182
    client_secret=held only by the site
    code_verifier=the secret itself

  returns
    access_token, refresh_token, id_token
The first leg goes through the browser and is visible to the person, to extensions and to anything watching. The second does not go through the browser at all. Notice that the secret verifier appears only on the second leg, while only its hash appeared on the first.

What each step proves

Now the useful exercise. Walk the same flow and ask, at each step, which

party has proved what to which other party. The answers are more lopsided

than people expect.

The lesson stops here

3 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Who You Are, What You May Do, and Who Remembers
  2. 02What Each Kind of Proof Actually Resistsopening only
  3. 03The Thing the Browser Carriesopening only
  4. 04The Token That Answers for Itselfopening only
  5. 05Two Tokens Beat Oneopening only
  6. 06Borrowing Somebody Elses Proofyou are here
  7. 07The Request Your Browser Sent for Somebody Elseopening only
  8. 08Making Somebody Stop Being Signed Inopening only

Read alongside