SolidOS / SolidOS/solidos

Add "TrustedApp-Prompt" for pod-hosted apps of same origin

Open
#107 1 comment 0 reactions 1 assignee View on GitHub

@timea-solid is already working on this.

Since Mar 8, 2022.

enhancement
Dominant language
JavaScript
Stars
146
Forks
21
PR merge metrics
No merged PRs in 30d

Description

Following a short discussion on [1], I would like to summarise the issue I ran into:

Problem:

When serving the an app from a Solid Pod, e.g. at https://uvdsl.host.name/apps/solid-test-app/
agent that use the same IDP as the agent providing the app, e.g. https://alice.host.name/profile/card#me
does not receive the "Add as Trusted App"-Prompt.

Hence, she will receive 403 Origin Unauthorized error messages when accessing private resources.

Once, she added https://uvdsl.host.name as a trusted app in her profile, everything works as expected.

Side note: the user https://uvdsl.host.name/profile/card#me apparently does not need to add the app as a trusted app as it is served from his pod. I never ran into any issues here.

Possible Solution:

Add the "Add as Trusted App"-Prompt also to "same origin apps" if the authority of the app URI does not match the authority of the user's webId, e.g.

App URI: https://uvdsl.solid.aifb.kit.edu/apps/solid-test-app/
uvdsl WebId: https://uvdsl.host.name/profile/card#me
Alice WebId: https://alice.host.name/profile/card#me

Alice should get prompted as the authority her WebId (alice.host.name) does not match the app URI's authority (uvdsl.host.name).
uvdsl should not get prompted as there is not need for that anyway.

Thank you for giving us NSS.

[1] https://github.com/uvdsl/solid-test-app/issues/1

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.