Using the shared sign-in in an app
Every app under *.totenkode.no receives the cookie tk_session. It is a JWT signed with ES256; verify it with the public key at
https://login.totenkode.no/.well-known/jwks.json.
Claims
iss=https://login.totenkode.no,aud=totenkode.nosubandemail: the email address, lower caseapps: the apps the person may use;*is every appexp: 12 hours after sign-in
In each request
- No valid cookie: redirect to
https://login.totenkode.no/?return=<the URL asked for>. - Valid, but
appshas neither the app's name nor*: answer 403. - Sign out: link to
https://login.totenkode.no/logout?return=<url>.
return must be an https URL on totenkode.no or a name under it; anything else is ignored.
Spring Boot
Copy verify/TotenkodeSession.java from the totenkode/platform/login repository (it needs com.nimbusds:nimbus-jose-jwt) and see its README. The influencer app uses it as is.