Public Client + PKCE

Dummy App A untuk uji browser-side OIDC flow.

Login dilakukan lewat Authorization Code + PKCE, lalu sesi lokal disimpan server-side di Redis agar back-channel logout bisa menutup sesi lintas aplikasi.

Client ID

prototype-app-a

Authorize URL

https://dev-sso.timeh.my.id/authorize

Callback URL

https://app-a.timeh.my.id/auth/callback

Response Type

code

PKCE Method

S256

Session Strategy

Redis-backed local session with HttpOnly session cookie

Logout Sync

Back-channel logout by sid via signed logout_token