# Use discourse for SSO in a non-web app?

**URL:** <https://meta.discourse.org/t/use-discourse-for-sso-in-a-non-web-app/40584>\
**Category:** Development\
**Created:** [3월 4, 2016, 6:46오후 UTC](https://meta.discourse.org/t/use-discourse-for-sso-in-a-non-web-app/40584 "2016-03-04T18:46:50Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![DeanMarkTaylor](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/deanmarktaylor/32/102462_2.png) [@DeanMarkTaylor](https://meta.discourse.org/u/DeanMarkTaylor)\
**Post date:** [3월 5, 2016, 9:22오전 UTC](https://meta.discourse.org/t/use-discourse-for-sso-in-a-non-web-app/40584/9 "2016-03-05T09:22:38Z")

</div>

Pretty sure every target platform has a “WebView” of some kind to do this, no problems on mobile.

Certainly with a Full-Screen Windows app it would be possible to use a WebView without changing resolution or needing to minimize.  
Although the popup authentication windows that Facebook, Google, etc create might look a bit odd depending on resolution.

The devil is in the details.

* * *

You could always simply mimic the requests that a browser would make.

You can complete this yourself on the command line using CURL.

The following assumes:

- Your Discourse instance is at `https://try.example.com`
- Username is `ExampleUser1`
- Password is `ExamplePasswordXX!`

### 1. Initially make a request to get both `_forum_session` cookie and `CSRF-Token`

```shell
curl -v "https://try.example.com/session/csrf" -H "X-CSRF-Token: undefined" -H "Referer: https://try.example.com/" -H "X-Requested-With: XMLHttpRequest"

```

### 2. Note the `_forum_session` cookie value from header and `csrf` JSON result in body

```plaintext
< Set-Cookie: _forum_session=XXXXXXXXXYYYYYYYYZZZZZZ; path=/; HttpOnly; Secure

{"csrf":"XXXXXXXXaaaaaaaaaaaaXXXXXXXXXXXXXX=="}

```

### 3. Attempt a login request

```shell
curl -v "https://try.example.com/session" -H "Origin: https://try.example.com" -H "X-CSRF-Token: XXXXXXXXaaaaaaaaaaaaXXXXXXXXXXXXXX==" -H "Cookie: _forum_session=XXXXXXXXXYYYYYYYYZZZZZZ" -H "Content-Type: application/x-www-form-urlencoded; charset=UTF-8" -H "Referer: https://try.example.com/" -H "X-Requested-With: XMLHttpRequest" --data "login=ExampleUser1&password=ExamplePasswordXX!"

```

### 4. Read the response

Expect a JSON response back containing the users basic profile info.

---

_[View the full topic](https://meta.discourse.org/t/use-discourse-for-sso-in-a-non-web-app/40584)._
