Goiabada test app
Each page follows one guide of the docs, against https://demo-auth.goiabada.dev.
Not configured yet: WEB_CLIENT_SECRET, WEB2_CLIENT_SECRET, SERVICE_CLIENT_SECRET. See .env.example.
- Web app: a confidential client. Add sign-in to a web app, Sign users out, Require two-factor authentication
- Second web app: another confidential client. Single sign-on across clients
- SPA: a public client, in the browser. Add sign-in to a SPA or mobile app
- Service: the client credentials flow. Protect an API
- The API: answers only a token carrying its permission.