Mint and verify short-lived RS256 user tokens.
ExApps sign after AppAPI auth; Microservices check a static public key or an OIDC issuer and forward the same bearer. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+25
@@ -0,0 +1,25 @@
|
||||
# go-usertoken
|
||||
|
||||
User tokens an ExApp mints for Microservices. Import `gitea.neitzel.de/konrad/go-usertoken`.
|
||||
|
||||
## Language
|
||||
|
||||
**User token**:
|
||||
A short-lived RS256 JWT whose `sub` is the Nextcloud user id. Optional `groups` is a snapshot taken when the ExApp minted it. Microservices forward the same token to each other.
|
||||
_Avoid_: AppAPI secret, access token (too broad), session
|
||||
|
||||
**Caller**:
|
||||
The user id, username, and optional groups read from a verified user token.
|
||||
_Avoid_: Requesting user (that is the AppAPI name, before a token exists), principal
|
||||
|
||||
**Signer**:
|
||||
The ExApp-side minter. It holds the only private key.
|
||||
_Avoid_: issuer (the `iss` string), identity server
|
||||
|
||||
**Static key**:
|
||||
The verify mode that checks a user token with a configured RSA public key and a fixed `iss` string. No discovery URL.
|
||||
_Avoid_: JWKS, OIDC
|
||||
|
||||
**OIDC issuer**:
|
||||
The verify mode that discovers keys at an identity server (for example Keycloak). One Microservice process uses this mode or static key, not both.
|
||||
_Avoid_: running discovery on the ExApp
|
||||
Reference in New Issue
Block a user