Authentication and sessions
In the usual Reskyt model, the identity system and the login remain those of the client’s ecommerce. The app does not maintain its own identity system or a parallel user base: it shows the authentication flow inside the WebView.
What the native layer can add
Section titled “What the native layer can add”The capabilities in this section are modules and integrations that are incorporated when they are part of the project scope. None of them is included by default.
Biometrics. Biometric login stores credentials using the operating system’s secure storage and allows signing in with Face ID, Touch ID or fingerprint instead of typing them.
Social login. The Facebook Login and Google Sign-In modules enable native sign-in with those providers.
Device identification. The uuid_app cookie identifies the installation
and allows it to be linked to a profile in your database, which makes it
possible to keep the session open between app launches.
Session persistence
Section titled “Session persistence”The session is kept with the same mechanisms as on your website (cookies and browser storage), but inside the app container.
SSO and OAuth
Section titled “SSO and OAuth”If your store already uses SSO or OAuth, the flow runs inside the app just as it does on the web. Flows that open an external browser and return to the app require review during project setup.
Who is responsible for what
Section titled “Who is responsible for what”| Area | Responsible |
|---|---|
| Identity system and user base | Your ecommerce |
| Login, registration and recovery flow | Your ecommerce |
| Password policy and session expiry | Your ecommerce |
| Biometric layer and native social login, when integrated | Reskyt |
| Form selectors for biometrics | Configured by Reskyt on your website |
| Changes to the login flow | Your team, notifying Reskyt |
If the login form changes, the biometrics configuration may stop recognising it. Redesigns should be communicated in advance.