Files
go-usertoken/README.md
T

42 lines
1.3 KiB
Markdown

# go-usertoken
Short-lived RS256 user tokens from a Nextcloud ExApp to Go Microservices.
Import: `gitea.neitzel.de/konrad/go-usertoken` (package `usertoken`).
```bash
go get gitea.neitzel.de/konrad/go-usertoken
```
The ExApp mints a token after AppAPI has named the user. Each Microservice checks that token. One process trusts either a static public key or an OIDC issuer. The same bearer is forwarded when a Microservice calls another.
- [Guide](docs/guide.md) — how to mint and how to verify
- [API](docs/api.md) — every exported symbol
- [Domain language](CONTEXT.md)
Procedure and claim rules: Knowledge `platforms/nextcloud/exapps/authentication.md`.
## Included
- [ExApp](docs/guide.md#exapp) — mint a token, including key generation
- [Microservice](docs/guide.md#microservice) — verify a bearer and forward it
## Excluded
- AppAPI and `APP_SECRET`
- Choosing the Nextcloud user (the ExApp already has that id)
## Testing
Unit tests cover minting, static verification, and the HTTP and gRPC interceptors. OIDC tests do not need a live issuer unless a test starts one.
`go test ./...` fails when [`docs/api.md`](docs/api.md) does not match the exported API. Regenerate it with:
```bash
UPDATE_API_DOCS=1 go test -run TestAPIDoc -count=1
```
## Related
- Knowledge `platforms/nextcloud/exapps/authentication.md` — procedure and claims