How does Single Sign-On (SSO) work?
newsletter.techworld-with-milan.com
newsletter.techworld-with-milan.com
Leaves out some of the more complicated aspects of SSO, such as:
* Logout (surprisingly complicated, see this video for more: https://m.youtube.com/watch?v=96m7DDQBW0U )
* Linking accounts (if you let someone login with Google, then also let them login with email and they use the same Gmail address, is it one account or two?)
* Verifying account ownership (more important for if anyone can register under any email address)
* Setting up the SSO integration (how does Google know how to trust Trello?)
What am I missing?
0: the fedcm work is going to impact redirects. https://github.com/fedidcg/FedCM/blob/main/explainer.md
Btw. even if you target entra id or other idp‘s it’s always a good idea to also have a way to trigger the single logout, some people might need it, so it is good to have it behind an Option. Also you should at least implement the backchannel logout. But as said none is really a requirement and often you just use an upfront idp as a second way to login and maintain your own user data in this case single logout is just an addon not a necessity.
This is what WorkOS helps solve for developers. It's like Stripe for SAML (and other enterprise features)
https://workos.com/single-sign-on
Happy to chat with anyone who's interested! mg@workos.com
Agreed that every SP is slightly different. There's a reason the SAML spec is 800+ pages, it covers a lot of variations. Since it has not been substantially updated since, there are some legacy choices (hello XML).
We also maintain an open source java SAML library: https://github.com/FusionAuth/fusionauth-samlv2
SSO is simple on the surface and complex once you peel it back!
* OAuth2 in action: https://www.manning.com/books/oauth-2-in-action which is great because it build an OAuth2 server in an accessible language, JavaScript
* Solving identity in modern applications: https://link.springer.com/book/10.1007/978-1-4842-8261-8 which is dry but a great book about the modern identity lifecycle and an overview of the relevant protocols
* I co-authored this ebook about the different modalities of OAuth: https://leanpub.com/themodernguidetooauth if you email me (email in profile), happy to get you a PDF for free
* Security Engineering is great for some of the fundamentals, about hashing, for instance: https://www.cl.cam.ac.uk/~rja14/book.html (haven't finished it yet, though)
Finally joining the OAuth mailing list is a great way to keep on top of the evolution of the protocols: https://www.ietf.org/mailman/listinfo/oauth