This article assumes that you have already set up an SSO application with Disqus. If you haven’t yet, please start with this article: Integrating Single Sign-On. This article only covers what is different when you embed SSO with Boards.
Access to Single Sign-On (SSO) is currently available as an add-on for users with a Business level subscription.
Single Sign-On lets visitors use their site account with Disqus Boards without signing in to Disqus separately. Boards uses the same SSO application, remote domain, and HMAC payload as Disqus Comments. You do not create a second SSO user store.
What stays the same
Remote domain (one per Organization)
API application: Domains, SSO Domain, OAuth permissions
Payload: Base64 JSON + HMAC-SHA1 + Unix timestamp, space-separated
Required user fields:
id,username,emailOptional:
avatar,url,profile_urlPayloads expire after two hours
Logout payload: signed empty JSON object
{}Debug: disqus.com/api/sso and the SSO debug checklist
User deletion: same overwrite or
deleteSSOUserflow as comments
Note: For local testing of Boards, Disqus Staff can help add every Boards page origin to the API application Domains list (localhost / 127.0.0.1 for local testing).
What is different
Comments | Boards |
|
|
|
|
|
|
Comments forum | Dedicated |
|
|
Boards is usually embedded on an entire page. Comment threads inside a discussion are mounted by Boards using the shortname boards-<shortname>. Set this.sso on disqus_boards_config and Boards will copy page.api_key, page.remote_auth_s3, and this.sso into comment embeds generated in Boards discussions, including when the visitor is logged out (api_key plus sso.url is enough for the publisher login row). There is no need to add a second disqus_config SSO block on those pages, as our Boards code takes care of that for you.
Boards SSO Script
Load this before boards.js. Generate remote_auth_s3 on your server. Never put your Disqus secret key in page JavaScript.
<div id="disqus-boards-host"></div>
<script>
window.disqus_boards_config = function () {
this.page.api_key = 'YOUR_PUBLIC_API_KEY';
this.page.remote_auth_s3 = 'SIGNED_MESSAGE SIGNATURE TIMESTAMP';
};
</script>
<script>
(function () {
if (document.getElementById('disqus_boards_script')) return;
var d = document, s = d.createElement('script');
s.id = 'disqus_boards_script';
s.src = 'https://YOUR_SHORTNAME.disqus.com/boards.js';
(d.head || d.body).appendChild(s);
})();
</script>
Use the public key of the API application that owns your SSO domain. That application must be in the same Organization as the Boards forum.
After login or logout
Put a freshly signed
remote_auth_s3on that object (keepapi_key).Call
DISQUS_BOARDS.authenticate().
window.disqus_boards_config.page.api_key = 'YOUR_PUBLIC_API_KEY';
window.disqus_boards_config.page.remote_auth_s3 = newPayload;
DISQUS_BOARDS.authenticate();
That is the Boards equivalent of DISQUS.reset({ reload: true, config: function () { … } }).
Logging out of SSO is a signed empty payload, not blank fields and not omitting headers:
window.disqus_boards_config.page.api_key = 'YOUR_PUBLIC_API_KEY';
window.disqus_boards_config.page.remote_auth_s3 =
'BASE64({}) SIGNATURE TIMESTAMP'; // no id / username
DISQUS_BOARDS.authenticate();
Publisher login and logout links (this.sso)
Set this.sso when you want Boards to show your site login next to (or instead of) Disqus login.
SSO-lite (publisher login + Disqus login)
window.disqus_boards_config = function () {
this.page.api_key = 'YOUR_PUBLIC_API_KEY';
this.page.remote_auth_s3 = 'SIGNED_MESSAGE SIGNATURE TIMESTAMP';
this.sso = {
name: 'Sign in with this site',
url: 'https://yoursite.com/sso/login/',
logout: 'https://yoursite.com/sso/logout/',
width: 800,
height: 400,
// icon: 'https://yoursite.com/favicon.png',
// useRedirect: true,
};
};name— Label on the publisher login row.icon— Small logo in the same slot as the Disqus mark (recommended).button— Full-row image. Prefericonplusnameso the row matches Disqus login. A missing or brokeniconfalls back to a generic glyph (a 404iconURL can show as a broken image).url— Your login page. Default: popup. The popup should close itself when login finishes; Boards then reloads the host page so you can inject the newremote_auth_s3.useRedirect— Iftrue, Boards navigates this tab tourland appendsreturn_url(the current page). After login, send the user back toreturn_url.logout— Your logout page. Boards navigates here exactly as written. It does not addreturn_url. Your logout page should clear the site session and send the user back (for example viadocument.referrer, restricted to your origin). Iflogoutis missing or invalid, Boards falls back to Disqus logout.width/height— Popup size only. Unused in redirect mode.
Do not rely on the comments 143×32 “SSO login button” PSD for Boards. Boards is a text row with a 22px glyph, not that chip.
SSO-only (SSO_AUTH_ONLY)
Ask your Disqus account manager to enable SSO Auth required (SSO_AUTH_ONLY) on boards-<shortname>. That is the forum for the Boards shell and for comment threads inside discussions, so one setting covers both (the shell via Boards; the embed via Disqus).
When it is enabled:
Disqus login is hidden.
If
this.sso.urlis set, visitors can open New Discussion, write a draft, and are asked to sign in with your site when they publish. The draft survives the reload that finishes popup or redirect login.If
this.sso.urlis missing, Boards hides the anonymous auth card and New Discussion (same idea as comments hiding the comment box).
this.sso = {
url: 'https://yoursite.com/sso/login/',
logout: 'https://yoursite.com/sso/logout/',
useRedirect: true,
};
Examples
Language samples for signing the payload: SSO code examples in the comments article