SSO and multiple discourse apps

That first S in SSO stands for single. One server is the the source of truth for all of the clients. There is no way to “use this local log in unless there isn’t one and then go try go log in somewhere else.”

I don’t quite understand, but I think so.

When a user logs in to a site where something else is the SSO server, they are redirected there and log in there and then, if things are configured correctly, get transparently redirected back to the site where they started.

If a third site were the SSO server, then the login flow would be the same on all sites, as they’d all be redirected to the SSO server.

2 Likes