Mint and verify short-lived RS256 user tokens.

ExApps sign after AppAPI auth; Microservices check a static public key or an OIDC issuer and forward the same bearer.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-09-28 14:03:52 +02:00
co-authored by Cursor
parent 92feaa6915
commit f082561cc6
13 changed files with 1091 additions and 0 deletions
+10
View File
@@ -0,0 +1,10 @@
// Package usertoken mints and checks the short-lived RS256 user token an ExApp
// sends to Microservices.
//
// An ExApp calls [NewSignerFromEnv] and [Signer.Mint] after AppAPI has named
// the user. A Microservice calls [FromEnv] and [Auth.Middleware]. One process
// trusts either a static public key or an OIDC issuer, not both.
//
// The procedure, claims, and environment variables are in
// knowledge/platforms/nextcloud/exapps/authentication.md.
package usertoken