EarthLink Network Unifies Auth and Authorization Across All Products Under One Platform

EarthLink Network has consolidated authentication and authorization for all its products into a single in-house Identity Provider called ELN ID, developed over three months from mid-2026. What began as a basic organization-management app evolved after more than fifteen OAuth client requests made clear that per-product integration rules were unsustainable. Key decisions included banning hidden iframes for silent Single Sign-On in favor of top-level redirects, after SameSite=Lax cookie restrictions caused iframe-based login checks to always fail. Terms-of-service consent versioning was standardized using opaque strings compared only for exact equality, preventing integrated products from independently interpreting version order. The overhaul also fixed two bugs — admin-group data vanishing after token refresh and admin screens rejecting users whose API calls were otherwise succeeding — by centralizing all role and consent logic on the server side.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in