Federated sign-in crosses provider, browser, application session, and record-permission boundaries. This track follows a permit reviewer through a one-use callback, signed identity assertion, renewable app session, and account-method changes. Each step owns a different failure and recovery path.
Topics in this track
- Authorization Code, PKCE, and Callback Binding — Bind each authorization response to its initiating browser session and one-use code verifier.
- ID Token Verification and Stable Account Identity — Verify signed identity claims and key local accounts by issuer plus subject, not mutable email.
- Refresh Token Rotation and App Session Boundary — Keep external token renewal separate from revocable browser sessions and handle rotation races.
- Federated Account Linking, Logout, and Revocation — Require an explicit signed-in linking ceremony and distinguish local logout from provider logout.
Prerequisite paths
Federated Login Callback Boundary; Identity and Application Security; Authorization and Tenant Boundaries.
Practice and check
Build Project: federated permit reviewer sign-in and test the boundaries in Web Development: federated identity and session contracts quiz.
