Decisions

Why the accounts plugin works the way it does. What it does: README.

Why is the login its own plugin?

Your relay login is used by tunnels, boxes and share links, and none of them owns it. In the tunnel plugin, making boxes would mean installing tunnels, and removing tunnels would lose the login boxes need. Link's test for a seam is whether you'd still use the code without the plugin it sits in; the login fails it in any plugin but its own. So the accounts plugin keeps the login and its file, and the others ask lnk auth ... --json for what they need from it (contracts).

Why does the tunnel get the login token itself?

A tunnel connects to the relay with the login token, so it needs the token, not a short-lived one. It asks lnk auth relay --json rather than reading the file, so the file and its Keychain item stay the accounts plugin's alone. The token reaches only a process of the same user, who can read the file already.

Why does a new login wait for a machine already signed in?

The relay's approval page shows who is logging in, from where, and warns about another network, but a person can still be talked into approving. A machine already signed in is something a phisher doesn't have: once an account has one, a login approved in the browser waits for it too (lnk auth approve), shown the same device, address and code. Tricking someone then takes two approvals, in two places, and the second one says where the login came from. An account's first login has no machine to ask, so it is the browser's alone, as before.

Any of the account's machines can confirm, not one chosen as the "main" one: a person signed in on a laptop and a desktop shouldn't need a particular one at hand. The new machine names a few of them, so you know where to look.

Why does lnk auth approve deny when you answer no?

A login you didn't start is the reason to look, so the answer that isn't yes ends it: the new machine is told it was denied, and on which machine. One you did start costs only another lnk auth login. Given a code (lnk auth approve <code>), it confirms that one without asking: typing the code is the comparison the question asks for.

How does a box sign in without asking you twice?

lnk box start runs lnk auth login on the box while you watch, and this machine is signed in already. It asks the relay for a ticket (lnk auth ticket --json), a confirmation given ahead, and hands it to the box's login. Once you approve that login in the browser as the same account, it needs nothing more. A ticket works once, for 10 minutes, and only for its own account; by itself it gets no token, since the browser's approval is still needed. A machine logging in again, still holding its token, confirms its own login the same way. Matching the box by its address or name instead would let someone else's login started at the same moment pass as the box's.

What does an older lnk get?

It can't show a confirmation step, so a relay that needs one refuses it when the browser's approval comes in, and the approval page says the same: upgrade, log in again, confirm with lnk auth approve. Leaving it waiting would look like a hang. Where no machine is signed in, it logs in as it always did. A new lnk says it can wait (confirm in its start), which is how the relay tells them apart.

How does someone who lost every machine get back in?

Through the operator: link-relay admin logout <user> revokes all of the account's login tokens, and its next login needs only the browser. Anything a person could do alone from a new machine, a phisher could too.