Skip to main content

Overview

What the service does

The id service answers two questions for every other service: who is this, and what have they agreed to let you know?

Outline
  • Sections:
    • The shape
    • What each piece does
    • What it does not do

Read more

Signing in

A service sends someone to /oidc/auth, as with any OpenID Provider.

Outline
  • Sections:
    • With a passkey
    • With an email
    • After signing in
    • Signing out

Read more

What people share

The first time a service asks for something, the person sees each scope it asked for, what it would share — their actual email address, their actual phone number — and chooses.

Outline
  • Sections:
    • What is remembered
    • Asked again
    • Taking it back
    • Details kept here

Read more

Services

Every service that signs in is a group of environment variables.

Outline
  • Sections:
    • In a monolith
    • Rotating a secret
    • Every client uses PKCE
    • Refused at start

Read more

Claims from other services

The id service keeps who someone is.

Outline
  • Sections:
    • Owning a scope
    • A claims review
    • Trusting the request
    • When a service is down

Read more

Policy

Every authorization decision the id service makes goes through lib/server/policy.ts, which uses @fairgarden/policy⁠ (external site)(github.com/fairgarden/policy): each decision is asked the way Open Policy Agent expects, so the built-in rules can be replaced by Rego without touching anything that asks, and every one is recorded.

Outline
  • Sections:
    • The decisions
    • Reasons are shown
    • The organization's rules
    • Anyone may read it
    • Every decision is recorded
    • Failing closed

Read more

Keys

Tokens are signed with RS256 keys, and cookies with secrets, and both live in the database and look after themselves.

Outline
  • Sections:
    • Rotation
    • After a leak
    • Keys in a secret store instead

Read more

Database

Drizzle, over pg: any Postgres.

Outline
  • Sections:
    • Locally
    • Migrations

Read more

Deploying

Deploying on Vercel with Neon, white-labelling the pages, running in a monolith, and sending email.

Outline
  • Sections:
    • On Vercel, with Neon
    • White-labelling
    • In a monolith
    • Email

Read more

Testing

Everything the tests need is in this repository: no other FairGarden service, no database server, no mail server.

Outline
  • Sections:
    • Unit tests
    • Browser tests

Read more