Skip to content

feat: tiny sign-in app at /signin.html - #15

Merged
melvincarvalho merged 1 commit into
gh-pagesfrom
feat-signin-app
May 16, 2026
Merged

melvincarvalho merged 1 commit into
gh-pagesfrom
feat-signin-app

Conversation

@melvincarvalho

Copy link
Copy Markdown
Contributor

Summary

Replaces the "Sign in → /idp → 'go find a Solid app like Pilot' → Pilot → type pod URL → back to /idp → me/me" sequence (6+ context switches) with a real OIDC client baked into jspod (2 context switches: welcome → /idp form → me/me → done).

Welcome page's Sign in button now points at /signin.html. Verified end-to-end in browser — sign-in form renders, credentials accepted, returns to welcome page authenticated.

What signin.html does

  • Imports solid-oidc (zero-dep, AGPL-3.0-or-later, same org as JSS and jspod) from version-pinned jsdelivr URL
  • Fresh visit: tries session.restore(). If no prior session (throws "Missing refresh data" on a clean IndexedDB — handled), calls session.login(thisPod, /signin.html). solid-oidc handles dynamic client registration, PKCE, DPoP keypair generation
  • Browser redirects to /idp/auth with OAuth params → JSS now renders its real login form (Passkey / Schnorr / username + password)
  • Return visit (?code= in URL): session.handleRedirectFromLogin() exchanges code for DPoP-bound tokens, stores in IndexedDB, redirects to /

ACLs

signin.html ships with a sibling signin.html.acl giving public read (mirrors JSS's index.html.acl pattern), so the page is reachable before any session exists.

Known follow-up (not in this PR)

After sign-in, welcome.html's locked-tile probe still uses plain fetch() and so /private/, /inbox/, /settings/ stay dimmed. Auth-aware probes would need solid-oidc on welcome.html too — or, better, a separate /account.html dashboard (Pivot-style) as the post-sign-in destination. Filing as the next thing.

Test plan

  • Welcome page Sign in button points at /signin.html
  • /signin.html served with public-read ACL (HTTP 200 unauth)
  • Fresh visit kicks off OIDC flow; JSS /idp/interaction/<token> form renders
  • me/me accepted; round-trips back to /signin.html?code=...
  • solid-oidc reachable on jsdelivr at the pinned version
  • Bumped to 0.0.17
  • Reviewer: npx jspod@0.0.17 after merge + publish, end-to-end click-through

Refs #1

Replaces the "Sign in → /idp → 'go find a Solid app'" detour with a
real OIDC client baked into jspod. Welcome page's Sign in button now
points at /signin.html.

What signin.html does:
- Imports solid-oidc (zero-dep, AGPL, same JavaScriptSolidServer
  org as JSS and jspod) from a version-pinned jsdelivr URL
- On fresh visit: tries to restore prior session; if none, calls
  session.login(thisPod, /signin.html). solid-oidc handles dynamic
  client registration, PKCE, DPoP. Browser is redirected to JSS's
  /idp/auth with OAuth params — at which point JSS renders its
  real Passkey / Schnorr / username+password form
- On return (?code= present): session.handleRedirectFromLogin()
  exchanges code for DPoP-bound tokens, stores them in IndexedDB,
  redirects user back to the pod root

Collapses ~6 context switches (welcome → /idp message → Pilot →
type pod URL → /idp form → me/me → back) down to 2 (welcome →
/idp form → me/me → back).

ACL: signin.html ships with a sibling signin.html.acl giving
public read (mirrors JSS's index.html.acl pattern), so the page
is reachable before any session exists.

Implementation:
- signin.html (~4 KB) — single-file static page
- signin.html.acl — public-read for the page itself
- welcome.html — Sign in href changes from ./idp to ./signin.html
- index.js — always-overwrite copy alongside welcome.html
- package.json — files whitelist + 0.0.17 bump

Known follow-up (not in this PR): after sign-in, the welcome
page's locked-tile probe still uses plain fetch and so the tiles
stay dimmed. Auth-aware probes need solid-oidc on welcome.html
too, OR a separate /account.html dashboard. Tracking as next step.

Refs #1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant