I have a Rails API and a client written in React that is embedded to website A. I want to use single sign-on so that users logging in to website A and going to my React app are automatically logged in to the API. I am using Devise to manage users and Doorkeeper to handle OAuth2.
Here is the scenario wanted :
User logs in to website A which is a provider
User goes to React app (embedded in website A), some user info is passed by website A to React app
If user is unknown to Rails API, check that provider is website A and store user via Devise
Get access token for this user and user info from API and send back to React App
I cannot add routes to website A so it's not possible to install a usual OAuth2 flow.
My idea was to pass a signature identifying user from website A to the React app, and sending it to the API to authenticate user. I tried using the doorkeeper-grants_assertion gem but I cannot wrap my head around this problem.
Which grant flow should I use for the user in that case ? How to integrate this strategy to omniauth ?
Any help would be much appreciated.