Overview
- What the service does - (Outline, Contents)
- Signing in - (Outline, Contents)
- What people share - (Outline, Contents)
- Services - (Outline, Contents)
- Claims from other services - (Outline, Contents)
- Policy - (Outline, Contents)
- Keys - (Outline, Contents)
- Database - (Outline, Contents)
- Deploying - (Outline, Contents)
- Testing - (Outline, Contents)
What the service does
The id service answers two questions for every other service: who is this, and what have they agreed to let you know?
Outline
- Sections:
- The shape
- What each piece does
- What it does not do
Signing in
A service sends someone to /oidc/auth, as with any OpenID Provider.
Outline
- Sections:
- With a passkey
- With an email
- After signing in
- Signing out
What people share
The first time a service asks for something, the person sees each scope it asked for, what it would share — their actual email address, their actual phone number — and chooses.
Outline
- Sections:
- What is remembered
- Asked again
- Taking it back
- Details kept here
Services
Every service that signs in is a group of environment variables.
Outline
- Sections:
- In a monolith
- Rotating a secret
- Every client uses PKCE
- Refused at start
Claims from other services
The id service keeps who someone is.
Outline
- Sections:
- Owning a scope
- A claims review
- Trusting the request
- When a service is down
Policy
Every authorization decision the id service makes goes through
lib/server/policy.ts, which uses
@fairgarden/policy (external site)(github.com/fairgarden/policy): each decision is
asked the way Open Policy Agent expects, so the built-in rules can be replaced
by Rego without touching anything that asks, and every one is recorded.
Outline
- Sections:
- The decisions
- Reasons are shown
- The organization's rules
- Anyone may read it
- Every decision is recorded
- Failing closed
Keys
Tokens are signed with RS256 keys, and cookies with secrets, and both live in the database and look after themselves.
Outline
- Sections:
- Rotation
- After a leak
- Keys in a secret store instead
Database
Drizzle, over pg: any Postgres.
Outline
- Sections:
- Locally
- Migrations
Deploying
Deploying on Vercel with Neon, white-labelling the pages, running in a monolith, and sending email.
Outline
- Sections:
- On Vercel, with Neon
- White-labelling
- In a monolith
Testing
Everything the tests need is in this repository: no other FairGarden service, no database server, no mail server.
Outline
- Sections:
- Unit tests
- Browser tests