Files
go-usertoken/CONTEXT.md
T
konradandCursor f082561cc6 Mint and verify short-lived RS256 user tokens.
ExApps sign after AppAPI auth; Microservices check a static public key or an OIDC issuer and forward the same bearer.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-28 14:03:52 +02:00

26 lines
1.0 KiB
Markdown

# go-usertoken
User tokens an ExApp mints for Microservices. Import `gitea.neitzel.de/konrad/go-usertoken`.
## Language
**User token**:
A short-lived RS256 JWT whose `sub` is the Nextcloud user id. Optional `groups` is a snapshot taken when the ExApp minted it. Microservices forward the same token to each other.
_Avoid_: AppAPI secret, access token (too broad), session
**Caller**:
The user id, username, and optional groups read from a verified user token.
_Avoid_: Requesting user (that is the AppAPI name, before a token exists), principal
**Signer**:
The ExApp-side minter. It holds the only private key.
_Avoid_: issuer (the `iss` string), identity server
**Static key**:
The verify mode that checks a user token with a configured RSA public key and a fixed `iss` string. No discovery URL.
_Avoid_: JWKS, OIDC
**OIDC issuer**:
The verify mode that discovers keys at an identity server (for example Keycloak). One Microservice process uses this mode or static key, not both.
_Avoid_: running discovery on the ExApp