b4281445ccbd39dda53c2661a1b1746eded64595
Co-authored-by: Cursor <cursoragent@cursor.com>
go-usertoken
Short-lived RS256 user tokens from a Nextcloud ExApp to Go Microservices.
Import: gitea.neitzel.de/konrad/go-usertoken (package usertoken).
go get gitea.neitzel.de/konrad/go-usertoken
The ExApp mints a token after AppAPI has named the user. Each Microservice checks that token. One process trusts either a static public key or an OIDC issuer. The same bearer is forwarded when a Microservice calls another.
- Guide — how to mint and how to verify
- API — every exported symbol
- Domain language
Procedure and claim rules: Knowledge platforms/nextcloud/exapps/authentication.md.
Included
- ExApp — mint a token, including key generation
- Microservice — verify a bearer and forward it
Excluded
- AppAPI and
APP_SECRET - Choosing the Nextcloud user (the ExApp already has that id)
Testing
Unit tests cover minting, static verification, and the HTTP and gRPC interceptors. OIDC tests do not need a live issuer unless a test starts one.
go test ./... fails when docs/api.md does not match the exported API. Regenerate it with:
UPDATE_API_DOCS=1 go test -run TestAPIDoc -count=1
Related
- Knowledge
platforms/nextcloud/exapps/authentication.md— procedure and claims
Languages
Go
100%