ExApps sign after AppAPI auth; Microservices check a static public key or an OIDC issuer and forward the same bearer. Co-authored-by: Cursor <cursoragent@cursor.com>
26 lines
1.0 KiB
Markdown
26 lines
1.0 KiB
Markdown
# go-usertoken
|
|
|
|
User tokens an ExApp mints for Microservices. Import `gitea.neitzel.de/konrad/go-usertoken`.
|
|
|
|
## Language
|
|
|
|
**User token**:
|
|
A short-lived RS256 JWT whose `sub` is the Nextcloud user id. Optional `groups` is a snapshot taken when the ExApp minted it. Microservices forward the same token to each other.
|
|
_Avoid_: AppAPI secret, access token (too broad), session
|
|
|
|
**Caller**:
|
|
The user id, username, and optional groups read from a verified user token.
|
|
_Avoid_: Requesting user (that is the AppAPI name, before a token exists), principal
|
|
|
|
**Signer**:
|
|
The ExApp-side minter. It holds the only private key.
|
|
_Avoid_: issuer (the `iss` string), identity server
|
|
|
|
**Static key**:
|
|
The verify mode that checks a user token with a configured RSA public key and a fixed `iss` string. No discovery URL.
|
|
_Avoid_: JWKS, OIDC
|
|
|
|
**OIDC issuer**:
|
|
The verify mode that discovers keys at an identity server (for example Keycloak). One Microservice process uses this mode or static key, not both.
|
|
_Avoid_: running discovery on the ExApp
|