Repository navigation
feat: tiny sign-in app at /signin.html - #15
Merged
Merged
Conversation
Replaces the "Sign in → /idp → 'go find a Solid app'" detour with a real OIDC client baked into jspod. Welcome page's Sign in button now points at /signin.html. What signin.html does: - Imports solid-oidc (zero-dep, AGPL, same JavaScriptSolidServer org as JSS and jspod) from a version-pinned jsdelivr URL - On fresh visit: tries to restore prior session; if none, calls session.login(thisPod, /signin.html). solid-oidc handles dynamic client registration, PKCE, DPoP. Browser is redirected to JSS's /idp/auth with OAuth params — at which point JSS renders its real Passkey / Schnorr / username+password form - On return (?code= present): session.handleRedirectFromLogin() exchanges code for DPoP-bound tokens, stores them in IndexedDB, redirects user back to the pod root Collapses ~6 context switches (welcome → /idp message → Pilot → type pod URL → /idp form → me/me → back) down to 2 (welcome → /idp form → me/me → back). ACL: signin.html ships with a sibling signin.html.acl giving public read (mirrors JSS's index.html.acl pattern), so the page is reachable before any session exists. Implementation: - signin.html (~4 KB) — single-file static page - signin.html.acl — public-read for the page itself - welcome.html — Sign in href changes from ./idp to ./signin.html - index.js — always-overwrite copy alongside welcome.html - package.json — files whitelist + 0.0.17 bump Known follow-up (not in this PR): after sign-in, the welcome page's locked-tile probe still uses plain fetch and so the tiles stay dimmed. Auth-aware probes need solid-oidc on welcome.html too, OR a separate /account.html dashboard. Tracking as next step. Refs #1
This was referenced May 16, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the "Sign in → /idp → 'go find a Solid app like Pilot' → Pilot → type pod URL → back to /idp → me/me" sequence (6+ context switches) with a real OIDC client baked into jspod (2 context switches: welcome → /idp form → me/me → done).
Welcome page's Sign in button now points at
/signin.html. Verified end-to-end in browser — sign-in form renders, credentials accepted, returns to welcome page authenticated.What signin.html does
solid-oidc(zero-dep, AGPL-3.0-or-later, same org as JSS and jspod) from version-pinned jsdelivr URLsession.restore(). If no prior session (throws "Missing refresh data" on a clean IndexedDB — handled), callssession.login(thisPod, /signin.html). solid-oidc handles dynamic client registration, PKCE, DPoP keypair generation/idp/authwith OAuth params → JSS now renders its real login form (Passkey / Schnorr / username + password)?code=in URL):session.handleRedirectFromLogin()exchanges code for DPoP-bound tokens, stores in IndexedDB, redirects to/ACLs
signin.htmlships with a siblingsignin.html.aclgiving public read (mirrors JSS'sindex.html.aclpattern), so the page is reachable before any session exists.Known follow-up (not in this PR)
After sign-in,
welcome.html's locked-tile probe still uses plainfetch()and so/private/,/inbox/,/settings/stay dimmed. Auth-aware probes would need solid-oidc onwelcome.htmltoo — or, better, a separate/account.htmldashboard (Pivot-style) as the post-sign-in destination. Filing as the next thing.Test plan
/signin.html/signin.htmlserved with public-read ACL (HTTP 200 unauth)/idp/interaction/<token>form rendersme/meaccepted; round-trips back to/signin.html?code=...npx jspod@0.0.17after merge + publish, end-to-end click-throughRefs #1