<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web-Auth on Ars magna</title>
    <link>https://arsmagna.xyz/categories/web-auth/</link>
    <description>Recent content in Web-Auth on Ars magna</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 30 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://arsmagna.xyz/categories/web-auth/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Wallet-native authentication</title>
      <link>https://arsmagna.xyz/apps/web-auth/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arsmagna.xyz/apps/web-auth/</guid>
      <description>&lt;p&gt;Every step below runs the real verification pipeline — nothing here is a canned result.&lt;/p&gt;&#xA;&#xA;&lt;h2 id=&#34;quick-guide&#34;&gt;&#xA;    Quick guide&#xA;    &lt;a class=&#34;&#34; href=&#34;#quick-guide&#34;&gt;&#xA;        &lt;i class=&#34;fa fa-chain&#34; aria-hidden=&#34;true&#34;&gt;&lt;/i&gt;&#xA;    &lt;/a&gt;&#xA;&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;Connect a wallet.&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Sign up.&lt;/strong&gt; Your wallet will prompt you to sign a small JSON message. The&#xA;pipeline log on the right shows all six verification stages passing.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Log in.&lt;/strong&gt; Same idea, a fresh nonce each time.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Try the &amp;ldquo;wrong&amp;rdquo; one on purpose.&lt;/strong&gt; Sign up again with the same address,&#xA;or log in before ever signing up. Both buttons are always clickable —&#xA;the demo deliberately doesn&amp;rsquo;t pre-check which one applies and disable&#xA;the other, because that check &lt;strong&gt;is&lt;/strong&gt; the `address` pipeline stage: a&#xA;duplicate signup or an account-less login gets rejected live, in the&#xA;log, based on the signed message itself. Hiding that behind a&#xA;pre-flight check would defeat the point of watching it happen.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Prove ownership.&lt;/strong&gt; Available once you&amp;rsquo;re signed in — this is the &amp;ldquo;prove&#xA;it&amp;rsquo;s still you&amp;rdquo; re-authentication for a sensitive action or proving ownership&#xA;of specific assets inside an address you control.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Demo scenarios&lt;/strong&gt; — do these &lt;strong&gt;after&lt;/strong&gt; signing up, so the account exists&#xA;and the failure you see is the one the button names, not an earlier&#xA;&amp;ldquo;no account&amp;rdquo; rejection:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Attempt login with a forged origin&lt;/strong&gt; — builds a real, validly-signed&#xA;message whose `uri` field doesn&amp;rsquo;t match this page&amp;rsquo;s real origin, and&#xA;shows the backend rejecting it specifically at the `uri` stage.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Replay the last signed message&lt;/strong&gt; — resubmits the exact same signed&#xA;bytes without asking the wallet to sign again, and shows the backend&#xA;rejecting it at the `nonce` stage (single-use nonces stop replay).&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;strong&gt;Disconnect&lt;/strong&gt; (in the wallet panel) drops the connection and ends the&#xA;current session, so you can connect a different wallet or address and try&#xA;the whole flow again from a clean state.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
