actuallyfrank blog
writing in publicno analytics on this pagerss still works
All posts
changelog

One place to sign in

one-place-to-sign-in

Every app on this domain used to ship its own sign-in machinery: a /login page, a byte-identical OAuth callback route, its own sign-out action. Adding a third app meant writing all of it a third time, and adding two more entries to the Supabase redirect allowlist.

Sessions were already shared — one cookie, scoped to actuallyfrank.io and everything under it, so signing in once really did sign you in everywhere. What was missing was a single honest place to do it.

So the proof-of-concept profile app became apps/account, moved to account.actuallyfrank.io, and became the only app allowed to change auth state. Everything else links to it and reads the session it produces.

The one genuinely tricky part was coming back. Sending someone from the blog to account and then back to the blog means the next parameter has to name a URL on a different host, which the old same-origin-path rule could not express. It now takes an absolute URL, checked against an allowlist: HTTPS, and a hostname that is actuallyfrank.io or a subdomain of it. Anything else quietly lands you somewhere safe instead.