Skip to content

User Story: Sign up to RP using a one-tap widget #12

@berilee

Description

@berilee

User story

As a user I want to sign up to rp.example.com using the one-tap widget flow. The user is already signed into the IDP.

  1. The user is signed into their IDP in their current browser
  2. The user visits rp.example.com, which they have never signed up to before
  3. The user sees the one-tap widget showing continue as bob
  4. The user taps continue as bob in the widget
  5. The user sees a “verify” message for 1s in the widget
  6. The user sees the sign-up button in a new popup
  7. The user clicks sign-up and is presented with the RPs screen as a successfully signed up and signed in user

Alternative, user cancels sign-up

  1. The user is signed into their IDP in their current browser
  2. The user visits rp.example.com, which they have never signed up to before
  3. The user sees the one-tap widget showing continue as bob
  4. The user taps continue as bob in the widget
  5. The user sees a “verify” message for 1s in the widget
  6. The user sees the sign-up button in a new popup
  7. The user cancels either by:
    a) Clicking the back button in the browser and then sees the RP login page showing the IDP list to sign-up with
    b) Clicking the “x” button and then sees the original page without being signed in

Context of the story

Assumptions

  • The new RP user already has an account with the one-tap IDP
  • The new RP user is a logged-in user with the one-tap IDP
  • The RP has integrated the one-tap authentication flow from the IDP

Scenario

  • Consumer: Shows up on various sites on the internet prompting for authentication
  • (Does one-tap get used elsewhere?)

Should this be considered sanctioned or unsanctioned tracking?

  • Unknown / TBD

Explicit list of parties involved

  • RP
  • UA
  • IDP
  • A new RP user

Privacy Implications

  • The new RP user should provide consent to sign-in with the IDP before any messages are sent
  • The IDP needs to show the Terms of Service and Privacy Policy for the RP
  • The IDP needs to inform the user of any shared information
  • The RP should not know the user accessed the one-tap flow until the user provides consent

Complicating characteristics

[TBD]

Additional Information

[N/A]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions