Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 619175
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 13, 20262026-05-13T18:37:35+00:00 2026-05-13T18:37:35+00:00

Its not explicitly cross domain sessions that I am looking for, but its the

  • 0

Its not explicitly cross domain sessions that I am looking for, but its the easiest way to explain what it is I want.

I have a system which creates websites.
The websites are hosted across lots of different servers.

Users can create their account and then they can create lots of websites.
They could create

http://www.mysite.com
subdomain.mysite.com
and create lots of different sites.

Some times, sites will be COMPLETELY different from one another, however some times, the sites will in fact be so closely linked, that they should probably be considered the same site.

For example:
(Different domain entirely)
mysite-news.com
mysite-blog.com
or (Same domain, different subdomain)
news.mysite.com
blog.mysite.com

What I need is a way for users where they want, to create a federation of sort, which allows by clicking a check box, that they want to allow cross site logins. I cannot change configs unless its a permanent change and won’t affect other sites, because 1000s of sites will be affected.

What do you think would be the best way to support this?
OpenID, SSO?

I need something which is simple for sites to create a ‘federation’ and then allow their sign ins to be cross domain. If someone wants to join then they can.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-13T18:37:35+00:00Added an answer on May 13, 2026 at 6:37 pm

    OpenID provides some nice features, but unfortunately, the cross-domain behavior you’re looking for isn’t something that you’ll find in a standard OpenID implementation. One of the primary design principles of OpenID is that the provider not disclose any information about the user without their explicit consent*, and so any reputable OpenID provider will never tell mysite-news.com that you’ve already logged in to mysite-blog.com without asking for user approval.

    [In technical terms, what’s happening here is that mysite-news.com and mysite-blog.com are, conceptually, in the same security “realm”, but OpenID identifies realms by URL patterns, and since they’re on different domains they don’t match.]

    And that doesn’t give you the user experience you want. There are some previous answers that do a fine job of outlining the kind of system you need here:

    • Cross-domain login […]
    • Transparent user session over several sites […]

    In short, you’ll be setting some sort of auth service on login.mysite.com to answer queries from mysite-news.com and mysite-blog.com. There are still a few ways you can take advantage of OpenID within this.

    1. The redirect-to-login-and-return-a-signed-token flow described there is exactly what OpenID does. So you could still use an OpenID implementation to do all that managing of signed tokens and replay protection, your client sites just get to skip the initial “discovery” part of OpenID and always redirect users to the login.mysite.com provider. And login.mysite.com gets to skip the step of “do I trust mysite-blog.com”, because it’s a special-purpose provider that can have its own whitelist of sites it always works with. OpenID would be purely behind-the-scenes here, users would never know that OpenID was somehow involved.

    2. login.mysite.com could, in turn, use OpenID to ask users to authenticate against their OpenID provider (whether it be Google or Yahoo or a specialist like myOpenID). From there it would look like a standard OpenID login and you’d get all the benefits, the disadvantage is that your login-redirect chain gets a little longer (and correspondingly slower). Them’s the breaks.

    Good luck. This is a question that comes up fairly frequently, and I’ve yet to find a really great reference implementation that I can point people to, so if you find something good do come back and let us know.

    Lastly, obligatory link to Matasano Chargen’s screenplay on the subject.

    [*] the recent Google Buzz fiasco is a good reminder of what happens when you surprise users about who their information is being shared with.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I'm defining an iterator type that does not store its current value explicitly. Instead,
I got this weird problem where System.Action cant be resolved when its not explicitly
Its not really a subtraction I'm looking for. And I know its not a
I keep seeing documentation saying that its not possible to send to a remote
Got this line of code here but its not working. private void Button_Click(object sender,
I added a regex validator but its not showing anything on the page, basically
I went to download SharpZipLib assemblies but it looks like its not on SourceForge.
Hi I am trying to run WSAD in Client login but its not starting
I'm looking for a cross-platform database engine that can handle databases up hundreds of
How are cross-domain web tracking services implemented (e.g., for behavioral advertising ), now that

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.