Check the same user token on gRPC as on HTTP.
Microservices can forward the raw bearer from the interceptor context. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -2,8 +2,9 @@
|
||||
// sends to Microservices.
|
||||
//
|
||||
// An ExApp calls [NewSignerFromEnv] and [Signer.Mint] after AppAPI has named
|
||||
// the user. A Microservice calls [FromEnv] and [Auth.Middleware]. One process
|
||||
// trusts either a static public key or an OIDC issuer, not both.
|
||||
// the user. A Microservice calls [FromEnv] and [Auth.Middleware] or
|
||||
// [Auth.UnaryServerInterceptor]. One process trusts either a static public
|
||||
// key or an OIDC issuer, not both.
|
||||
//
|
||||
// The procedure, claims, and environment variables are in
|
||||
// knowledge/platforms/nextcloud/exapps/authentication.md.
|
||||
|
||||
Reference in New Issue
Block a user