Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

With oauth probably not since the state doesn't transfer with cookies. You send the user to the IdP with a postback in the URL then when the user logs it it sends them back to the original site with some data that depends on the flow you chose.

Your login cookie as far as the IdP is concerned lives on oauth.thirdparty.net and on a successful login the app issues you your own session token that lives on myapp.com.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: