One sign-in for decePubClient: the root JWT exchanged for a persona's token
The first-party client signs in on /clientapi and exchanges that JWT on /oauth/token (RFC 8693, subject_token_type jwt, avatar_id) for one persona's Mastodon token. Only the seeded public application `decepub` holds the grant; RootJwtSubjectToken validates the JWT through RootJwt, which JwtBearer now shares (signature, lifetime, ban, deletion, session stamp). The issued token names the avatar, never the root. Owner decision recorded in ROADMAP; it supersedes "moving decePubClient onto the Mastodon API is out of scope". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
This commit is contained in:
1 parent
c7e8760ffe
commit
2cd75176a4
10 files changed
+432
-30
No files matched your search
@@ -1,10 +1,7 @@
|
||||
using Microsoft.AspNetCore.Authentication;
|
||||
using Microsoft.IdentityModel.Tokens;
|
||||
|
||||
using PrivaPub.Services;
|
||||
|
||||
using System.Text;
|
||||
|
||||
namespace PrivaPub.Extensions
|
||||
{
|
||||
public static class AddAuthExtension
|
||||
@@ -15,16 +12,7 @@ namespace PrivaPub.Extensions
|
||||
#if DEBUG
|
||||
options.RequireHttpsMetadata = false;
|
||||
#endif
|
||||
options.TokenValidationParameters = new()
|
||||
{
|
||||
ValidateIssuer = true,
|
||||
ValidateAudience = true,
|
||||
ValidateLifetime = true,
|
||||
ValidateIssuerSigningKey = true,
|
||||
ValidIssuer = configuration["AppConfiguration:Jwt:Issuer"],
|
||||
ValidAudience = configuration["AppConfiguration:Jwt:Audience"],
|
||||
IssuerSigningKey = new SymmetricSecurityKey(Encoding.UTF8.GetBytes(configuration["AppConfiguration:Jwt:Key"]))
|
||||
};
|
||||
options.TokenValidationParameters = RootJwt.Parameters(configuration);
|
||||
options.Events = new JwtEvents();
|
||||
});
|
||||
return builder;
|
||||
|
||||
Reference in new issue
Block a user