Files
go-usertoken/CONTEXT.md
T
konradandCursor f082561cc6 Mint and verify short-lived RS256 user tokens.
ExApps sign after AppAPI auth; Microservices check a static public key or an OIDC issuer and forward the same bearer.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 14:03:52 +02:00

1.0 KiB

go-usertoken

User tokens an ExApp mints for Microservices. Import gitea.neitzel.de/konrad/go-usertoken.

Language

User token: A short-lived RS256 JWT whose sub is the Nextcloud user id. Optional groups is a snapshot taken when the ExApp minted it. Microservices forward the same token to each other. Avoid: AppAPI secret, access token (too broad), session

Caller: The user id, username, and optional groups read from a verified user token. Avoid: Requesting user (that is the AppAPI name, before a token exists), principal

Signer: The ExApp-side minter. It holds the only private key. Avoid: issuer (the iss string), identity server

Static key: The verify mode that checks a user token with a configured RSA public key and a fixed iss string. No discovery URL. Avoid: JWKS, OIDC

OIDC issuer: The verify mode that discovers keys at an identity server (for example Keycloak). One Microservice process uses this mode or static key, not both. Avoid: running discovery on the ExApp