-
Notifications
You must be signed in to change notification settings - Fork 8
Open
Description
User story
As a user I want to sign up to rp.example.com using the one-tap widget flow. The user is already signed into the IDP.
- The user is signed into their IDP in their current browser
- The user visits rp.example.com, which they have never signed up to before
- The user sees the one-tap widget showing continue as bob
- The user taps continue as bob in the widget
- The user sees a “verify” message for 1s in the widget
- The user sees the sign-up button in a new popup
- The user clicks sign-up and is presented with the RPs screen as a successfully signed up and signed in user
Alternative, user cancels sign-up
- The user is signed into their IDP in their current browser
- The user visits rp.example.com, which they have never signed up to before
- The user sees the one-tap widget showing continue as bob
- The user taps continue as bob in the widget
- The user sees a “verify” message for 1s in the widget
- The user sees the sign-up button in a new popup
- The user cancels either by:
a) Clicking the back button in the browser and then sees the RP login page showing the IDP list to sign-up with
b) Clicking the “x” button and then sees the original page without being signed in
Context of the story
Assumptions
- The new RP user already has an account with the one-tap IDP
- The new RP user is a logged-in user with the one-tap IDP
- The RP has integrated the one-tap authentication flow from the IDP
Scenario
- Consumer: Shows up on various sites on the internet prompting for authentication
- (Does one-tap get used elsewhere?)
Should this be considered sanctioned or unsanctioned tracking?
- Unknown / TBD
Explicit list of parties involved
- RP
- UA
- IDP
- A new RP user
Privacy Implications
- The new RP user should provide consent to sign-in with the IDP before any messages are sent
- The IDP needs to show the Terms of Service and Privacy Policy for the RP
- The IDP needs to inform the user of any shared information
- The RP should not know the user accessed the one-tap flow until the user provides consent
Complicating characteristics
[TBD]
Additional Information
[N/A]
Metadata
Metadata
Assignees
Labels
No labels