Every app on this domain used to ship its own sign-in machinery: a /login
page, a byte-identical OAuth callback route, its own sign-out action. Adding a
third app meant writing all of it a third time, and adding two more entries to
the Supabase redirect allowlist.
Sessions were already shared — one cookie, scoped to actuallyfrank.io and
everything under it, so signing in once really did sign you in everywhere. What
was missing was a single honest place to do it.
So the proof-of-concept profile app became apps/account, moved to
account.actuallyfrank.io, and became the only app allowed to change auth
state. Everything else links to it and reads the session it produces.
The one genuinely tricky part was coming back. Sending someone from the blog to
account and then back to the blog means the next parameter has to name a URL
on a different host, which the old same-origin-path rule could not express. It
now takes an absolute URL, checked against an allowlist: HTTPS, and a hostname
that is actuallyfrank.io or a subdomain of it. Anything else quietly lands you
somewhere safe instead.