The first-party client signs in on /clientapi and exchanges that JWT on /oauth/token (RFC 8693, subject_token_type jwt, avatar_id) for one persona's Mastodon token. Only the seeded public application `decepub` holds the grant; RootJwtSubjectToken validates the JWT through RootJwt, which JwtBearer now shares (signature, lifetime, ban, deletion, session stamp). The issued token names the avatar, never the root. Owner decision recorded in ROADMAP; it supersedes "moving decePubClient onto the Mastodon API is out of scope". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LsXgEaXee4GCU1hwYgPJXw
21 lines
513 B
C#
21 lines
513 B
C#
using Microsoft.AspNetCore.Authentication;
|
|
|
|
using PrivaPub.Services;
|
|
|
|
namespace PrivaPub.Extensions
|
|
{
|
|
public static class AddAuthExtension
|
|
{
|
|
public static AuthenticationBuilder AddPrivaPubAuth(this AuthenticationBuilder builder, IConfiguration configuration)
|
|
{
|
|
builder.AddJwtBearer(options => {
|
|
#if DEBUG
|
|
options.RequireHttpsMetadata = false;
|
|
#endif
|
|
options.TokenValidationParameters = RootJwt.Parameters(configuration);
|
|
options.Events = new JwtEvents();
|
|
});
|
|
return builder;
|
|
}
|
|
}
|
|
} |