gitoriaLog in with ident

ident

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit51a7bcdf51a7bcdfident: Hybriel master 73267707 (#122); /code uses the new page() signature; pending address passed as parameter; once-checksmre51a7bcdf/CONCEPT.md

4.6 KB

  1. # ident — concept (from the creator, 2026-09-24)
  2. ident is a login to ident itself (email one-time code). Everything else happens inside ident.
  3. ident, tickets and gitoria are PWAs; on the phone ident can register for push notifications.
  4. ## In ident
  5. - **Account**: you log in to ident with an email code. **There is no registration**: the first
  6. successful OTP login creates the user with a default identity, then shows the name fields and
  7. clearly states they are optional.
  8. - **Time zone**: set to the browser's time zone at first ident use.
  9. - **Identities**: a user has a **default identity from the beginning**. If they don't create
  10. another one, that one is always chosen. An identity has **no mandatory fields**; it can have
  11. nickname, firstname, lastname and an **avatar** (creator, 2026-09-24: apps show it, e.g. in comments). Inside ident it has an **identity name** — that one is shown
  12. in the selector.
  13. - **One id per app**: an identity gets a different id for every app, so ids are not transferable
  14. between apps.
  15. - **Apps**: **any ident user can register apps**. An app gets an **API key**. It uses one of two flows.
  16. - **The app never exposes the identity id** — it uses it server side only.
  17. - **Notifications**: apps never get the real email. To send a notification in an app's name you need
  18. that app's API key and the identity id (the one for that app). The user reads them in ident's
  19. notifications inbox.
  20. - A notification has: **name**, **text**, optional **icon**, optional **action link**. The action link
  21. may be any link; the icon may come from any URL (creator, 2026-09-24).
  22. - Channels: the **app presets** the channels, the **user can overwrite** them.
  23. - **Default: every notification goes to the daily mail**, sent at **17:00 in the user's time zone**.
  24. - An app that wants to send **pushes directly must first register that kind of notification**
  25. (by its name).
  26. - **Urgent** notifications are sent immediately: **push** if the user has registered a push
  27. device, **email** otherwise — always within the user's switches (creator, 2026-09-24).
  28. - The daily mail at 17:00 in the user's time zone needs **time-zone support in Hybriel** (creator: "hybriel
  29. needs time zone support") — ident does not ship its own zone rules.
  30. - **Per-app page**: for each app and identity the user has a page showing when they registered
  31. in that app and all its notifications (by name), each with **push** and **email** switches, and
  32. on top **one override for all**.
  33. - **More fields**: if an app needs more data from the user, it asks for it itself when the user
  34. registers with their ident id. ident does not hand out more.
  35. - **Later**: merge user accounts, move an identity to another account.
  36. - **Later**: ident hands over identity properties to the app **during the first handshake** (creator,
  37. 2026-09-24: "ident does handover properties during the first handshake, just not yet").
  38. ## Flow 1: login button
  39. The app shows "login with ident", which sends you to ident and back.
  40. ## Flow 2: identity selector
  41. - The app's page includes a script from ident, configured with the app's API key.
  42. - The script fetches from ident. If the requesting website is registered as an app in ident and
  43. uses its API key, ident answers with the identities of the logged-in ident user.
  44. - The selector is displayed: a shadow-DOM element in ident's design, which the target website can
  45. restyle.
  46. - It first says "choose ident". When the user selects an identity, that is the login.
  47. - What happens then is up to the app: our apps just switch the frontend to logged in; others
  48. might do a reload.
  49. ## Decided 2026-09-24 (architect proposal, accepted by the creator)
  50. - **Selector knows the website is already logged in**: the host tells the selector (it knows its own
  51. session), e.g. `<ident-selector logged-in>` / a property. The selector sets no cookie of its own.
  52. Logout on the website = host resets the selector.
  53. - **Server-side check of a selection**: selecting hands the script a one-time code; the website's
  54. server exchanges it with ident for the identity id. The API key sits in a public script, so server
  55. calls (exchange, notifications) use a separate **app secret**.
  56. ## In the app
  57. The app creates its own user connected to that ident identity by storing the identity id (server side).
  58. ## Open
  59. - **Client-only apps** (no server to keep the identity id): not figured out yet (creator).
  60. ## Not this
  61. The mission-003 build (`{id, email, name}` handed to apps, no identities, apps as a config allow
  62. list, no selector, no inbox) was built without this concept. Its email-code login to ident and the
  63. button redirect flow can be reused; the rest is rebuilt from this document.

Branches

Latest commits

  • 51a7bcdfident: Hybriel master 73267707 (#122); /code uses the new page() signature; pending address passed as parameter; once-checksmre
  • 836f644fident#24: installable app (manifest, service worker, data-free offline /start), own iconmre
  • 8bebbbf2deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • cc063ea2deploy.sh: never send .git or .gitignore to Byrodinmre
  • 81b15b7bState of 2026-09-27, before the move to gitoriamre