# go-usertoken Short-lived RS256 user tokens from a Nextcloud ExApp to Go Microservices. Import: `gitea.neitzel.de/konrad/go-usertoken` (package `usertoken`). ```bash go get gitea.neitzel.de/konrad/go-usertoken ``` The ExApp mints a token after AppAPI has named the user. Each Microservice checks that token. One process trusts either a static public key or an OIDC issuer. The same bearer is forwarded when a Microservice calls another. - [Guide](docs/guide.md) — how to mint and how to verify - [API](docs/api.md) — every exported symbol - [Domain language](CONTEXT.md) Procedure and claim rules: Knowledge `platforms/nextcloud/exapps/authentication.md`. ## Included - [ExApp](docs/guide.md#exapp) — mint a token, including key generation - [Microservice](docs/guide.md#microservice) — verify a bearer and forward it ## Excluded - AppAPI and `APP_SECRET` - Choosing the Nextcloud user (the ExApp already has that id) ## Testing Unit tests cover minting, static verification, and the HTTP and gRPC interceptors. OIDC tests do not need a live issuer unless a test starts one. `go test ./...` fails when [`docs/api.md`](docs/api.md) does not match the exported API. Regenerate it with: ```bash UPDATE_API_DOCS=1 go test -run TestAPIDoc -count=1 ``` ## Related - Knowledge `platforms/nextcloud/exapps/authentication.md` — procedure and claims