Using the shared sign-in in an app

Every app under *.totenkode.no receives the cookie tk_session. It is a JWT signed with ES256; verify it with the public key at https://login.totenkode.no/.well-known/jwks.json.

Claims

In each request

  1. No valid cookie: redirect to https://login.totenkode.no/?return=<the URL asked for>.
  2. Valid, but apps has neither the app's name nor *: answer 403.
  3. Sign out: link to https://login.totenkode.no/logout?return=<url>.

return must be an https URL on totenkode.no or a name under it; anything else is ignored.

Spring Boot

Copy verify/TotenkodeSession.java from the totenkode/platform/login repository (it needs com.nimbusds:nimbus-jose-jwt) and see its README. The influencer app uses it as is.