Files

1.3 KiB

go-usertoken

Short-lived RS256 user tokens from a Nextcloud ExApp to Go Microservices.

Import: gitea.neitzel.de/konrad/go-usertoken (package usertoken).

go get gitea.neitzel.de/konrad/go-usertoken

The ExApp mints a token after AppAPI has named the user. Each Microservice checks that token. One process trusts either a static public key or an OIDC issuer. The same bearer is forwarded when a Microservice calls another.

Procedure and claim rules: Knowledge platforms/nextcloud/exapps/authentication.md.

Included

  • ExApp — mint a token, including key generation
  • Microservice — verify a bearer and forward it

Excluded

  • AppAPI and APP_SECRET
  • Choosing the Nextcloud user (the ExApp already has that id)

Testing

Unit tests cover minting, static verification, and the HTTP and gRPC interceptors. OIDC tests do not need a live issuer unless a test starts one.

go test ./... fails when docs/api.md does not match the exported API. Regenerate it with:

UPDATE_API_DOCS=1 go test -run TestAPIDoc -count=1
  • Knowledge platforms/nextcloud/exapps/authentication.md — procedure and claims