Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Examples added where linking services showcase their contextual linking

We're going to add a feature that will allow apps to work without the user needing to create or enter a password.

...


POST/v3/auth/email/signIn
auth
no authentication, public endpoint
body
{ "email": "<email.address>", "study": "<studyId>", "password": "<password>", "token" : "<token>" }
returns200with user session

412with user session

404
{ "statusCode": 404, "entityClass": "Account", "message": "Account not found.", "type": "EntityNotFoundException" }


If the token has been issued, retrieve the user's identity and return a session. Optionally, if a password value has also been submitted, reset the password before returning the session.

...

methodDescription
requestEmailSignIn(SignIn signIn)
  1. If functionality disabled, throw EndpointNotFoundException
  2. If email present, throw RateLimitExceededException
  3. create token, store in Redis mapped to email, TTL 1 minute
  4. send email using study template to supplied email address
emailSignIn(CriteriaContext context, SignIn signIn)
  1. Retrieve token from Redis using email
  2. If email or token missing, or token doesn't match supplied token, throw 404
  3. Update password, if supplied
  4. Delete Redis entry
  5. Return a user session

...

  1. User fills out survey on the web
  2. User signs up using their phone number (on the phone, or in the web page? I think this matters)
  3. SMS is sent which takes user to app store/googe play store so they can download the app
  4. After the app installed the information from the online portion is remembered (ex. consent has been filled out)

Alx: I don't think it's possible to do this. If you have documentation on this, please provide it. For example, branch.io is "fingerprinting" a device in order to re-establish state after an app install... I don't see how this will work if user starts on desktop, and then switches to their phone).

First Install- Native App to Native App

...

In both applications the implementation is fairly straightforward, Android Studio has a built in feature that allows you create and test domains on your app. iOS has docs that are also straightforward. Note: neither of these can be tested until the certiciate is in place. 

Other Considerations

There are several cases when deep links won't work, links inside the Gmail, Inbox and Facebook apps for instance.

...

The main selling point of these services is that they allow for keeping information known through install (contextual linking). It has yet to be determined how difficult/or not difficult this is to do without their services. 

branch io

Examples of contextual linking with branch io, the 'magra' example shows an actual link that was texted to recieve an app install link

google firebase

[Alx]: The issue we will have with this is straightforward. From the website, to collect consent, we need an identity, and for an identity, we'll need an email address or phone number. The workflow would look something like this:

...

  • sends SMS message to the phone number provided
  • when user enters SMS message, user is signed in to the account and verified
  • all the consent information that was gathered from web page and put in URL is used by app to sign consent
  • app receives back re-authentication token in sign in session

...

Example of contextual linking  with google firebase here they show an example of how someone could open the app on the web like so:

   <ahref="https://abc123.app.goo.gl/?link=https://example.com/content?item%3D1234&apn=com.example.android&ibi=com.example.ios">
   Open this page in our app!
</a>

      In this example we have the link embedded inside the web page, but for our purposes we would want it sent via sms.